When a cyberattack hits, most organizations default to the same first steps: isolate systems, call IT, notify leadership, and start restoring operations. Those are all critical—but there’s another decision that often gets delayed until it’s too late: when (and how) to contact law enforcement.
I’ve worked with companies through ransomware, business email compromise (BEC), insider incidents, and data theft. In many cases, law enforcement can help—but only if you engage them at the right time, with the right information, and with realistic expectations. The goal isn’t to “hand the problem off.” It’s to protect the business, preserve options, and reduce downstream damage.
Rule of thumb: If the incident involves extortion, stolen funds, significant data exposure, or a credible threat actor, you should strongly consider contacting law enforcement early—often within the first 24 hours.
Why Contact Law Enforcement at All?
Some executives hesitate because they fear operational disruption, reputational risk, or regulatory consequences. Those concerns are understandable—but in practice, law enforcement involvement can create real advantages.
What law enforcement can do
Help with recovery leads (known ransomware groups, decryptor availability, infrastructure indicators).
Coordinate with other agencies (financial fraud teams, international partners, intelligence units).
Support fund recovery efforts in wire fraud/BEC cases—especially if contacted quickly.
Create an official record that may help with insurance claims, banking disputes, and legal posture.
Advise on safe engagement when extortion or threats are involved.
What law enforcement typically will not do
Instantly recover your data or “take down” the attacker on your timeline.
Run your incident response—that remains your responsibility (and your IR firm’s job).
Guarantee financial recovery (but they can materially improve the odds if engaged early).
Before You Call: Do These Three Things First
You don’t need a perfect forensic report to contact law enforcement, but you do need to avoid making the situation worse.
1) Stabilize and preserve evidence
Do not wipe systems unless your incident response lead directs it.
Preserve logs (SIEM, firewall, VPN, identity provider, email, EDR).
Capture volatile evidence where possible (running processes, network connections) through your IR team.
Document a timeline: what you saw, when you saw it, and what actions were taken.
2) Identify the incident type (roughly)
Even a preliminary classification helps route you to the right place:
Ransomware/extortion
Business Email Compromise (BEC) / invoice fraud / wire fraud
Data breach (PII/PHI/customer data exposure)
Insider threat
DDoS or service disruption
Critical infrastructure impact
3) Align internally (quickly)
Before contacting law enforcement, ensure these stakeholders are in the loop:
Incident commander (internal or external IR lead)
General Counsel / outside breach counsel
Cyber insurance carrier (if applicable—many policies have notification requirements)
Executive sponsor (CIO/CISO/COO/CEO depending on severity)
Practical advice: If you have breach counsel, let them help coordinate the outreach. It can streamline communications and reduce the risk of sharing inaccurate information early.
Who to Contact—and When
Not all cyber incidents belong in the same lane. Here’s a practical guide to choosing between local police, federal agencies like the FBI, and other reporting options.
1) Contact Local Police When…
Local law enforcement is appropriate when the incident has a clear local nexus, immediate physical risk, or when you need an official report for documentation purposes.
You need a police report for insurance, banking, or legal documentation.
There’s an insider component involving theft, sabotage, or harassment tied to an identifiable person.
There are threats to people or facilities (doxxing, threats of violence, stalking, swatting risk).
Physical theft is involved (stolen laptops, devices, badges, or on-prem equipment).
How to approach local police: Be prepared that many departments have limited cyber specialization. You’re often contacting them to create an official record and to address any physical-world risk, not to run a full-scale cyber investigation.
2) Contact the FBI When…
If your business is facing ransomware, extortion, significant data theft, or large financial loss, the FBI is often the right call. The FBI also has the advantage of broader visibility into threat actor campaigns and can coordinate across jurisdictions.
Ransomware or extortion (including threats to leak data).
Large-scale wire fraud/BEC or repeated fraud attempts.
Material data breach involving regulated data (PII/PHI) or significant customer impact.
Nation-state or advanced threat indicators (targeted intrusion, unusual tradecraft, critical IP theft).
Critical infrastructure impact or public safety implications.
How to contact the FBI:
In an emergency: call your local FBI field office.
For internet crime reporting: submit to the FBI’s IC3 (Internet Crime Complaint Center) at ic3.gov.
Timing matters: In BEC/wire fraud, the first few hours are critical. If you suspect fraudulent wire activity, contact your bank immediately and contact the FBI/IC3 right away. The odds of freezing funds drop sharply with time.
3) Contact the U.S. Secret Service When…
Many people associate the Secret Service with physical protection, but they also investigate financial crimes—including cyber-enabled fraud.
Financial fraud and payment-related cybercrime (especially complex cases involving multiple accounts or rapid money movement).
Large-scale fraud rings targeting businesses (invoice manipulation, payroll diversion, etc.).
If you already have an FBI relationship, start there. But in some regions, Secret Service cyber/financial crime teams are exceptionally effective partners.
4) Contact CISA When…
CISA (Cybersecurity and Infrastructure Security Agency) is not law enforcement, but it’s a major federal resource—especially for organizations that support critical functions.
You are part of critical infrastructure or provide essential services.
You want technical guidance, alerts, and coordination support.
You need help with vulnerability exploitation events affecting many organizations.
CISA can be a strong partner for situational awareness and defensive support, while the FBI handles criminal investigation.
5) Contact State Authorities When…
Depending on your location and industry, you may need to notify:
State Attorney General or consumer protection offices (often tied to breach notification laws).
State regulators for financial services, healthcare, insurance, or education.
This isn’t “law enforcement” in the classic sense, but it’s part of the broader government response that businesses must manage after certain breaches.
A Simple Decision Framework for Businesses
If you’re deciding who to contact, use this practical matrix.
Call your local police if:
You need a police report for documentation.
You suspect an insider with a known identity.
There are physical threats, stalking, harassment, or facility risk.
Devices were physically stolen.
Call the FBI (field office) and/or file with IC3 if:
Ransomware/extortion is involved.
Funds were stolen (or a wire is in-flight).
There is significant data theft or a material breach.
You suspect an organized criminal group or nation-state actor.
Engage CISA if:
You need federal-level defensive coordination or guidance.
The incident affects essential services or broad supply chain exposure.
What Information to Provide (and What Not to)
What to have ready
Company details: legal name, location, key contacts.
Incident summary: what happened, when detected, current status.
Scope: systems impacted, business functions affected, number of endpoints/servers (approximate).
Indicators of compromise (IOCs): suspicious IPs/domains, file hashes, email headers, attacker notes.
Ransom note details: filenames, extensions, communication channels, wallet addresses (if present).
For BEC: fraudulent emails, headers, bank account details, wire confirmations, timeline.
Evidence preservation steps taken and whether an IR firm is engaged.
What to avoid
Speculating about attribution (“it was definitely X group”) unless confirmed by evidence.
Altering evidence (editing logs, deleting mailboxes, reimaging machines prematurely).
Negotiating impulsively with extortionists without a plan and professional guidance.
Operational reality: You can continue restoration and containment while law enforcement is engaged. The key is coordination—so your recovery doesn’t destroy the forensic trail.
Special Case: Business Email Compromise (BEC) and Wire Fraud
If there’s one category where speed and process matter most, it’s BEC. These cases are often recoverable—but only early.
If you suspect a fraudulent wire transfer
Immediately call your bank (do not rely on email) and request a recall/hold.
Contact the receiving bank if known (your bank can help coordinate).
Contact the FBI via your local field office and/or file an IC3 report at ic3.gov.
Preserve email evidence (full headers, mailbox rules, forwarding configurations, login logs).
Many organizations lose valuable hours debating whether it’s “bad enough” to report. In BEC, that delay can be the difference between recovery and a total loss.
Ransomware: When Law Enforcement Helps Most
Ransomware is more than encryption—it’s business interruption, extortion, and often data theft. Even if you don’t plan to pay, law enforcement can provide:
Threat intelligence context (group behavior, known tactics, potential decryption history).
Guidance on safe communications and risk factors (especially if data leak threats exist).
Coordination if the incident is part of a broader campaign.
Also note: paying a ransom may create legal and regulatory risk in certain circumstances. Your counsel and incident response team should guide that decision, and law enforcement can help you understand the broader threat landscape.
What About Individuals (Not Businesses)?
Individuals should also report cybercrime—especially when there’s financial loss, identity theft, stalking/harassment, or credible threats.
Individuals should contact local police when:
There are threats, harassment, stalking, doxxing, or extortion with personal safety concerns.
A device was stolen or there’s a known local suspect.
You need a police report for identity theft, banking claims, or documentation.
Individuals should report to the FBI/IC3 when:
You’ve suffered online financial fraud, wire fraud, crypto scams, or account takeover with loss.
You’re a victim of ransomware (yes, it happens to individuals too).
For identity theft-related issues, individuals may also use IdentityTheft.gov (FTC) to document and begin recovery steps. That’s not law enforcement, but it’s an important reporting and remediation pathway.
How to Make the Call: A Practical Script
When you contact law enforcement, clarity matters. Here’s a simple structure:
Who you are: “I’m calling from [Company], I’m [Role], and I’m authorized to report this incident.”
What happened: “We detected [ransomware/BEC/data theft] on [date/time].”
Current status: “Systems are [contained/offline], IR team is engaged, evidence is being preserved.”
Impact: “We have [estimated] endpoints affected, potential data exposure includes [types].”
Urgency driver: “Funds were transferred at [time]” or “We received an extortion demand with deadline [time].”
What you need: “We want to report and coordinate, and we can provide IOCs and logs securely.”
Common Mistakes Businesses Make When Involving Law Enforcement
Waiting too long—especially in wire fraud and extortion scenarios.
Calling without internal alignment, leading to conflicting statements and confusion.
Over-sharing prematurely without counsel/IR guidance, creating inaccuracies that are hard to unwind.
Assuming law enforcement will “handle it” instead of treating them as one workstream in your response.
Failing to preserve evidence—reimaging endpoints and losing logs before anyone can analyze them.
Conclusion: Treat Law Enforcement as a Force Multiplier
A cyberattack is already a high-stakes event: operational downtime, financial exposure, customer trust, and legal obligations collide fast. Contacting law enforcement isn’t about theatrics—it’s about keeping options open, improving the odds of recovery (especially with fraud), and ensuring you’re making decisions with the best available intelligence.
For most businesses: contact local police when you need an official report, there’s a physical-world component, or an insider is involved. Contact the FBI (and file with IC3) for ransomware, extortion, major fraud, and meaningful data theft. Bring in CISA when you need broader defensive coordination—particularly in critical infrastructure or widespread exploitation events.
Call to action: Don’t wait for the incident to figure this out. Build a “who-to-call” law enforcement and government contact plan into your incident response playbook now—field office numbers, escalation paths, and a checklist of what to preserve and share. The best time to establish those relationships is before you need them.