maryland state house

Ransomware Possession Would Become A Crime In Maryland Under Proposed Legislation

Lawmakers are trying to deter would-be hackers from carrying out cyber attacks that have paralyzed companies, hospital systems and local governments, including Baltimore’s city government.

After two years of ransomware wreaking havoc on local governments, companies, hospital systems and school districts across the country, including the Baltimore city government, Maryland lawmakers have had enough. State senators are considering a bill that would make it a crime to possess ransomware with the intention to use it in a malicious way.

It’s already illegal in Maryland to use ransomware in a way that costs victims money. The malware encrypts data on an organization’s systems until a ransom is paid and has cost organizations millions of dollars over the past few years.

Under Senate Bill 30, ransomware owners convicted of possession with malicious intent would face a penalty of up to 10 years in prison and/or a fine of up to $10,000, according to Capital News Service. Researchers who possess ransomware would be exempt from the criminal penalty.

Senators heard arguments about the bill, introduced by state Sen. Susan Lee, last week. Lee originally introduced the legislation in 2019 and said she has cleaned up the bill ahead of the 2020 legislative session.

“It’s important to establish so criminals know it’s a crime,” Lee, a Democrat, told CNS. “[The bill] gives prosecutors tools to charge offenders.”

Other states have already made possession of ransomware a criminal offense, including Michigan and Wyoming. There is no official research to indicate that the creation of criminal penalties has deterred hackers, but cybersecurity experts say it’s important to show that there are consequences for carrying out the crimes.

“It’s important to send that signal [to perpetrators],” Markus Rauschecker, the program director of the University of Maryland’s Center for Health and Homeland Security, told CNS. “[This bill] highlights the threat and how big it is.”

Committing a cyber attack in Maryland that results in a loss of more than $10,000 is already a felony carrying penalties of up to 10 years in prison and/or up to $10,000 in fines.

Members of the Senate Judicial Proceedings Committee said on Tuesday that they would consider changing ransomware possession from a misdemeanor to a felony due to its huge impact on organizations, according to CNS. Local governments and companies have lost millions on lost revenue and the cost of cybersecurity services to regain access to their data. That’s not including companies that have paid out ransoms, some of whom still did not regain full access to their data.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.