maryland state house

Ransomware Possession Would Become A Crime In Maryland Under Proposed Legislation

Lawmakers are trying to deter would-be hackers from carrying out cyber attacks that have paralyzed companies, hospital systems and local governments, including Baltimore’s city government.

After two years of ransomware wreaking havoc on local governments, companies, hospital systems and school districts across the country, including the Baltimore city government, Maryland lawmakers have had enough. State senators are considering a bill that would make it a crime to possess ransomware with the intention to use it in a malicious way.

It’s already illegal in Maryland to use ransomware in a way that costs victims money. The malware encrypts data on an organization’s systems until a ransom is paid and has cost organizations millions of dollars over the past few years.

Under Senate Bill 30, ransomware owners convicted of possession with malicious intent would face a penalty of up to 10 years in prison and/or a fine of up to $10,000, according to Capital News Service. Researchers who possess ransomware would be exempt from the criminal penalty.

Senators heard arguments about the bill, introduced by state Sen. Susan Lee, last week. Lee originally introduced the legislation in 2019 and said she has cleaned up the bill ahead of the 2020 legislative session.

“It’s important to establish so criminals know it’s a crime,” Lee, a Democrat, told CNS. “[The bill] gives prosecutors tools to charge offenders.”

Other states have already made possession of ransomware a criminal offense, including Michigan and Wyoming. There is no official research to indicate that the creation of criminal penalties has deterred hackers, but cybersecurity experts say it’s important to show that there are consequences for carrying out the crimes.

“It’s important to send that signal [to perpetrators],” Markus Rauschecker, the program director of the University of Maryland’s Center for Health and Homeland Security, told CNS. “[This bill] highlights the threat and how big it is.”

Committing a cyber attack in Maryland that results in a loss of more than $10,000 is already a felony carrying penalties of up to 10 years in prison and/or up to $10,000 in fines.

Members of the Senate Judicial Proceedings Committee said on Tuesday that they would consider changing ransomware possession from a misdemeanor to a felony due to its huge impact on organizations, according to CNS. Local governments and companies have lost millions on lost revenue and the cost of cybersecurity services to regain access to their data. That’s not including companies that have paid out ransoms, some of whom still did not regain full access to their data.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.