i. List of Law Enforcement Agencies, Governmental Bodies, Cybersecurity Organizations (to be notified)
1) United States of America
Federal Bureau of Investigation (FBI): FBI is the primary federal agency for investigating and responding to cybercrime incidents, including ransomware attacks.
Actionable Steps: Use the Internet Crime Complaint Center (IC3) to report the ransomware attack.
US Department of Homeland Security (DHS)- Cybersecurity and Infrastructure Security Agency (CISA): Report CISA in the event of ransomware attack. It plays an important role in coordinating responses to cyber incidents like ransomware and provides technical assistance.
Actionable Steps:-Engage CISA for incident response support, including guidance on containment, remediation.
Industry Specific Regulatory Authorities (eg, HIPAA, SEC, FTC): Depending on the industry, there are additional regulatory bodies that must be notified if the ransomware attack affects specific sectors like healthcare, finance, or consumer protection.
Health and Human Service (HHS) - HIPAA Breach Notification Notify HHS and file a breach notification within 60 days for a health related breach.
Securities and Exchange Commission (SEC) Notify SEC if ransomware attack impacts public companies.
Federal Trade Commission (FTC) Notify FTC if ransomware attack involves consumer data.
2) Europe
European Union Agency for Cybersecurity (ENISA) ENISA is tasked with supporting incident response teams across the EU and coordinating threat intelligence.
Europol (European Cybercrime Center): Report ransomware attack to Europool’s European Cybercrime Center (EC3) to assist with investigation and coordination across EU member states.
Information Commissioner’s Office (ICO) Report ICO if the ransomware attack compromised personal data or violates data protection law. Contact Information:- ICO: https://ico.org.uk Email: casework@ico.org.uk Breach Reporting: https://ico.org.uk/for-organisations/report-a-breach/
Australia
Australia Cyber Security Center (ASCS) ASCS is the primary authority for cybersecurity incidents including ransomware attacks in Australia. Contact Information:- ASCS: https://www.cyber.gov.au
Australian Federal Police (AFP) AFP is the national law enforcement agency responsible for a cyber investigation and crimes, including cyber crime, ransomware attacks. Contact Information:- AFP Cybercrime Operations: https://www.afp.gov.au/what-we-do/crime-types/cybercrime Email: cybercrime@afp.gov.au
Canada
Canadian Cyber Incident Response Center (CCIRC) CCIRC is the primary authority for cybersecurity incidents in Canada. Report the incident to CCIRC to receive immediate technical assistance and support in managing the ransomware attack. Contact Information:- CCIRC: https://www.cyber.gc.ca Email: ccric@cyber.gc.ca Incident Reporting: https://www.cyber.gc.ca/en/incident-management
Royal Canadian Mounted Police (RCMP) RCMP is Canada’s national law enforcement agency, responsible for enforcing federal laws, including cybercrime and ransomware. Contact Information:- RCMP National Cybercrime Coordination Center (NC3): https://www.rcmp-grc.gc.ca Email:- cybercrime@rcmp-grc.gc.ca
India
Indian Computer Emergency Response Team (CERT-In) CERT-In serves as the primary government agency for handling cybersecurity incidents and providing technical assistance and coordination. Contact Information: CERT-IN contact page:- https://www.cert-in.org.in/ Helpline:- 1800-11-2424 Email:- incident@cert-in.org.ins