{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T02:30:33Z","timestamp":1781490633332,"version":"3.54.1"},"reference-count":65,"publisher":"Institute for Operations Research and the Management Sciences (INFORMS)","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information Systems Research"],"published-print":{"date-parts":[[2026,3]]},"abstract":"<jats:p>Practice- and Policy-Oriented Abstract<\/jats:p>\n                  <jats:p>Ransomware attacks have emerged as one of the biggest threats to cybersecurity. Faced with business disruptions, many organizations accede to ransom demands, and in doing so, they embolden the attackers to launch more attacks, elevating the chance of a future breach for others. We study this externality using a multiperiod game among multiple firms, each of which has a choice to pay or not pay if breached in a particular period, its action having implications for future periods. How should a policymaker intervene to mitigate this externality, and is prohibition necessary? What might work or how it might work as a policy tool depends critically on the behavior of the attacker (extortionist). If the attacker is not strategic, fiscal interventions could work, and a complete prohibition on ransom payment is unnecessary. If the attackers are strategic, though, they may respond to the policymaker\u2019s tax\/subsidy in a manner that could increase victims\u2019 propensity to pay, rendering fiscal intervention ineffective as a policy lever. In such a case, prohibition may be the only way to mitigate the externality. Overall, our analysis provides a framework for comparing different types of policy interventions and raises concerns for policymakers and social planners to pause and ponder.<\/jats:p>","DOI":"10.1287\/isre.2024.1160","type":"journal-article","created":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T11:00:59Z","timestamp":1746183659000},"page":"20-43","source":"Crossref","is-referenced-by-count":1,"title":["\u201cExtortionality\u201d in Ransomware Attacks: A Microeconomic Study of Extortion and Externality"],"prefix":"10.1287","volume":"37","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5290-0578","authenticated-orcid":false,"given":"Debabrata","family":"Dey","sequence":"first","affiliation":[{"name":"KU School of Business, University of Kansas, Lawrence, Kansas 66045"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3174-8014","authenticated-orcid":false,"given":"Atanu","family":"Lahiri","sequence":"additional","affiliation":[{"name":"Jindal School of Management, University of Texas, Dallas, Texas 75080"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"109","reference":[{"key":"B1","doi-asserted-by":"publisher","DOI":"10.1007\/s00182-008-0118-5"},{"key":"B2","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1050.0440"},{"key":"B3","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1070.0771"},{"key":"B4","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.2022.4300"},{"key":"B5","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1060.0568"},{"key":"B6","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1070.0142"},{"issue":"3","key":"B7","first-page":"541","volume":"44","author":"Block W","year":"2000","journal-title":"New York Law Rev."},{"key":"B8","doi-asserted-by":"publisher","DOI":"10.38024\/arpe.106"},{"key":"B9","doi-asserted-by":"publisher","DOI":"10.1016\/0165-1765(88)90171-1"},{"key":"B10","doi-asserted-by":"publisher","DOI":"10.3390\/g10020026"},{"key":"B11","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyz009"},{"key":"B12","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222250211"},{"key":"B13","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.2021.4154"},{"key":"B14","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2015.0601"},{"key":"B15","unstructured":"Coker J (2024) 78% of organizations suffer repeat ransomware attacks after paying.\n                      Infosecurity Magazine\n                      (February 23), https:\/\/infosecurity-magazine.com\/news\/orgs-repeat-ransomware-paying."},{"key":"B16","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-349-20215-7_6"},{"key":"B17","unstructured":"Daniel M, Turner M (2021) Should ransomware payments be made illegal?\n                      Wall Street J\n                      . (September 7), https:\/\/www.wsj.com\/articles\/ransomware-payment-illegal-ban-11631047209."},{"key":"B18","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.2021.4027"},{"key":"B19","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222290204"},{"key":"B20","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2014\/38.2.12"},{"key":"B21","doi-asserted-by":"publisher","DOI":"10.1287\/ijoc.2014.0638"},{"issue":"1","key":"B22","first-page":"152","volume":"21","author":"Dhillon G","year":"2020","journal-title":"J. Assoc. Inform. Systems"},{"key":"B23","unstructured":"DiMolfetta D (2024) Ransomware payment debate resurfaces amid Change Healthcare incident.\n                      Nextgov\n                      (March 18), https:\/\/www.nextgov.com\/cybersecurity\/2024\/03\/ransomware-payment-debate-resurfaces-amid-change-healthcare-incident\/395026\/."},{"key":"B24","doi-asserted-by":"publisher","DOI":"10.1016\/j.geb.2011.09.008"},{"key":"B25","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0531(88)90093-2"},{"key":"B26","doi-asserted-by":"publisher","DOI":"10.2307\/25750693"},{"key":"B27","doi-asserted-by":"publisher","DOI":"10.1057\/s41268-017-0101-5"},{"key":"B28","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2017\/41.4.10"},{"key":"B29","doi-asserted-by":"publisher","DOI":"10.1145\/581271.581274"},{"key":"B30","doi-asserted-by":"publisher","DOI":"10.3390\/g8020023"},{"key":"B31","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2020.100204"},{"key":"B32","doi-asserted-by":"publisher","DOI":"10.23940\/ijpe.12.4.p355.mag"},{"key":"B33","doi-asserted-by":"publisher","DOI":"10.3982\/TE2151"},{"issue":"3","key":"B34","first-page":"1","volume":"7","author":"Hernandez-Castro J","year":"2020","journal-title":"Roy. Soc. Open Sci."},{"key":"B35","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2018.0806"},{"key":"B36","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1040.0357"},{"key":"B37","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.2015.2309"},{"key":"B38","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222250210"},{"key":"B39","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-349-20215-7_11"},{"key":"B40","doi-asserted-by":"crossref","unstructured":"Laszka A, Farhang S, Grossklags J (2017) On the economics of ransomware. Rass S, An B, Kiekintveld C, Fang F, Schauer S, eds.\n                      Decision Game Theory Security. GameSec 2017\n                      , Lecture Notes in Computer Science, vol. 10575 (Springer, Cham, Switzerland).","DOI":"10.1007\/978-3-319-68711-7_21"},{"key":"B41","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1120.0447"},{"key":"B42","doi-asserted-by":"crossref","unstructured":"Li X, Whinston AB (2020) The economics of cybercrime. Preprint, submitted June 11, http:\/\/dx.doi.org\/10.2139\/ssrn.3603694.","DOI":"10.2139\/ssrn.3603694"},{"issue":"2","key":"B43","first-page":"333","volume":"84","author":"Maskin ES","year":"1994","journal-title":"Amer. Econom. Rev."},{"key":"B44","doi-asserted-by":"publisher","DOI":"10.1145\/3691340"},{"key":"B45","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103670"},{"key":"B46","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2015.0587"},{"key":"B47","doi-asserted-by":"publisher","DOI":"10.1287\/mksc.7.2.141"},{"key":"B48","unstructured":"Morgan S (2023) Global ransomware damage costs predicted to exceed $265 billion by 2031.\n                      Cybercrime Magazine\n                      (July 7), https:\/\/cybersecurityventures.com\/global-ransomware-damage-costs-predicted-to-reach-250-billion-usd-by-2031\/."},{"key":"B49","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103162"},{"key":"B50","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2023.102724"},{"key":"B51","doi-asserted-by":"publisher","DOI":"10.1145\/3514229"},{"key":"B52","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222260205"},{"key":"B53","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1080.0174"},{"key":"B54","volume-title":"Games and Information: An Introduction to Game Theory","author":"Rasmusen E","year":"2007","edition":"4"},{"key":"B55","unstructured":"Ray S (2023) Ransomware attacks upgraded to \u2018national security threat\u2019 in new White House cybersecurity strategy.\n                      Forbes\n                      (May 2), https:\/\/forbes.com\/sites\/siladityaray\/2023\/03\/02\/ransomware-attacks-upgraded-to-national-security-threat-in-new-white-house-cybersecurity-strategy\/."},{"key":"B56","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3268535"},{"key":"B57","unstructured":"Seals T (2021) Multi-gov task force plans to take down the ransomware economy.\n                      Threatpost\n                      (April 29), https:\/\/threatpost.com\/gov-task-force-ransomware-economy\/165715\/."},{"key":"B58","doi-asserted-by":"publisher","DOI":"10.2307\/3312577"},{"key":"B59","unstructured":"Shi F (2020) Ransomware attacks: Why it should be illegal to pay the ransom.\n                      Dark Reading\n                      (February 4), https:\/\/www.darkreading.com\/risk\/ransomware-attacks-why-it-should-be-illegal-to-pay-the-ransom\/a\/d-id\/1336905?_mc=rss\\_x\\_drr\\_edt\\_aud\\_dr\\_x\\_x-rss-simple."},{"key":"B60","unstructured":"Shi F (2021) Threat spotlight: Ransomware trends.\n                      Barrcuda Blogs\n                      (August 12), https:\/\/blog.barracuda.com\/2021\/08\/12\/threat-spotlight-ransomware-trends\/."},{"key":"B61","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222220405"},{"key":"B62","unstructured":"Sussman B (2020) As ransomware payments double, some want them banned.\n                      Secureworld\n                      (January 27), https:\/\/www.secureworldexpo.com\/industry-news\/ransomware-payments-double-some-want-ransoms-payment-ban."},{"key":"B63","volume-title":"The Theory of Industrial Organization","author":"Tirole J","year":"1994"},{"key":"B64","unstructured":"Travers T (2023) Repeat ransomware attacks: What\u2019s putting victims at risk?\n                      Barracuda Blogs\n                      (March 28), https:\/\/blog.barracuda.com\/2023\/03\/28\/repeat-ransomware-attacks."},{"key":"B65","doi-asserted-by":"publisher","DOI":"10.1287\/opre.2016.1572"}],"container-title":["Information Systems Research"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/pubsonline.informs.org\/doi\/pdf\/10.1287\/isre.2024.1160","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T15:47:24Z","timestamp":1775144844000},"score":1,"resource":{"primary":{"URL":"https:\/\/pubsonline.informs.org\/doi\/10.1287\/isre.2024.1160"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":65,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["10.1287\/isre.2024.1160"],"URL":"https:\/\/doi.org\/10.1287\/isre.2024.1160","relation":{},"ISSN":["1047-7047","1526-5536"],"issn-type":[{"value":"1047-7047","type":"print"},{"value":"1526-5536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]}}}