An Act amending Title 18 (Crimes and Offenses) of the Pennsylvania Consolidated Statutes, in computer offenses, providing for the offense of ransomware; and imposing duties on the Office of Administration.
SB 415 creates new criminal penalties for ransomware attacks targeting Pennsylvania state government systems. It prohibits possessing, using, or threatening to use ransomware (defined as software blocking access or encrypting data for payment demands) with penalties ranging from misdemeanors to felonies based on the ransom amount ($10,000+ triggers felony charges). The law requires managed IT service providers to notify state agencies within one hour of detecting ransomware, and agencies to report attacks to police within two hours. These provisions aim to prevent, detect, and respond to cyberattacks on Commonwealth agencies while mandating public notification after incidents.
Bill status
in committee
1 of 4 stages cleared
Introduction
Mar 2025
Committee Review
Floor Vote
Governor
Introduced Mar 10, 2025
Last action Mar 10, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
1
Key actions
0
Committee
1
Mar 10, 2025
Committee
Referred to Judiciary
upper
1 primary · 6 co-sponsors
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about SB 415
Scope: PA
Hi! I can help you understand SB 415. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline