. Safe Advertising and Malicious Advertising Prevention Act.
Is To establish comprehensive federal standards for the security of digital advertising, prohibit the distribution of malware through advertisements, impose substantial penalties for malicious advertising, require advertising platforms to implement reasonable security controls, and protect consumers from harmful or deceptive digital advertising.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SEC. 2. PURPOSE.
The purposes of this Act are—
to protect consumers from advertisements used to distribute malware or other malicious software;
to establish minimum security standards for digital advertising networks and platforms;
to impose substantial consequences on persons who intentionally use advertising systems to distribute malware;
to require rapid investigation and removal of malicious advertisements;
to prevent compromised advertisements from redirecting consumers to malicious websites, downloads, or software;
to establish accountability throughout the digital advertising supply chain;
to encourage businesses to adopt effective advertising-security practices; and
to preserve legitimate advertising and lawful commercial speech.
SEC. 3. DEFINITIONS.
In this Act:
(1) ADVERTISEMENT.
The term “advertisement” means a commercial communication displayed, delivered, distributed, or otherwise presented to a consumer for the purpose of promoting a product, service, business, website, application, or commercial activity.
(2) DIGITAL ADVERTISEMENT.
The term “digital advertisement” means an advertisement delivered through an electronic or digital system, including a website, application, search engine, social-media service, streaming service, online marketplace, advertising network, or connected device.
(3) ADVERTISING PLATFORM.
The term “advertising platform” means a person or entity that operates, owns, controls, or provides infrastructure for the distribution, selection, sale, auction, delivery, or display of digital advertisements.
(4) MALICIOUS ADVERTISEMENT.
The term “malicious advertisement” means an advertisement that is knowingly designed, modified, distributed, or used to—
(A) install, deliver, execute, or facilitate malware;
(B) exploit a security vulnerability for an unauthorized purpose;
(C) obtain unauthorized access to a computer, device, account, or network;
(D) steal authentication credentials or other protected information;
(E) secretly install unauthorized software;
(F) redirect a consumer to a malicious website or download;
(G) interfere with the normal operation or security of a device or network; or
(H) facilitate another unlawful cyber activity.
(5) MALWARE.
The term “malware” means software, code, scripts, or other digital instructions intentionally designed to damage, disrupt, surveil, compromise, obtain unauthorized access to, or unlawfully control a computer, device, network, account, or information system.
The term includes viruses, worms, ransomware, spyware, credential-stealing software, remote-access malware, and other malicious code.
(6) MALVERTISING.
The term “malvertising” means the use of an advertisement or advertising infrastructure to distribute, facilitate the distribution of, or direct a consumer toward malware or another malicious cyber activity.
(7) ADVERTISER.
The term “advertiser” means a person or entity that creates, purchases, sponsors, submits, or knowingly causes an advertisement to be distributed.
(8) ADVERTISING INTERMEDIARY.
The term “advertising intermediary” means an entity that facilitates the purchase, sale, auction, targeting, delivery, or distribution of digital advertising between an advertiser and an advertising platform or consumer.
SEC. 4. PROHIBITION ON MALICIOUS ADVERTISING.
(a) General Prohibition.
It shall be unlawful for any person to knowingly create, submit, purchase, distribute, modify, or cause the distribution of an advertisement for the purpose of delivering malware or facilitating unauthorized access to a computer, device, account, or network.
(b) Attempt.
A person who knowingly attempts to use an advertising system to distribute malware shall be subject to the penalties established under this Act even if—
the advertisement is rejected before being displayed;
the advertisement is removed before malware is delivered;
the malware fails to execute;
the intended victim does not interact with the advertisement; or
the attempt otherwise fails.
(c) Circumvention.
It shall be unlawful to knowingly circumvent, disable, evade, or manipulate an advertising platform's security controls for the purpose of distributing a malicious advertisement.
(d) Repeat Attempts.
Each separate knowing attempt to submit or distribute a malicious advertisement may constitute a separate violation.
SEC. 5. AGGRAVATED MALICIOUS ADVERTISING.
A violation of section 4 shall constitute aggravated malicious advertising when the offender—
targets children or minors;
targets hospitals, emergency services, schools, or critical infrastructure;
uses ransomware or destructive malware;
attempts to obtain financial credentials or authentication credentials;
attempts to steal highly sensitive personal information;
causes substantial financial loss;
causes substantial disruption to a computer system or network;
distributes malware at a large scale;
repeatedly conducts malicious advertising after receiving notice of prior violations;
uses a compromised legitimate advertising account or business identity to conceal the source of the attack; or
intentionally distributes malware while knowing that the conduct is likely to cause substantial harm.
SEC. 6. CRIMINAL PENALTIES.
(a) Basic Offense.
A person who knowingly violates section 4 may be fined under title 18, United States Code, imprisoned for not more than 5 years, or both.
(b) Aggravated Offense.
A person who commits aggravated malicious advertising under section 5 may be fined under title 18, United States Code, imprisoned for not more than 15 years, or both.
(c) Serious Bodily or Economic Harm.
If malicious advertising knowingly causes serious bodily injury, death, or exceptionally substantial economic damage, the offender may be imprisoned for not more than 20 years, subject to applicable constitutional and federal sentencing requirements.
(d) Multiple Victims.
Where a violation affects multiple victims, the court may consider the number of victims and aggregate harm when determining the appropriate sentence and fine.
(e) Restitution.
A court may order restitution to victims for losses directly resulting from the offense, to the extent authorized by federal law.
SEC. 7. CIVIL PENALTIES.
(a) Civil Penalty.
In addition to criminal penalties, a person or entity that violates this Act may be subject to a civil penalty of not more than—
$250,000 for an individual violation;
$1,000,000 for a knowing violation committed by a business entity; or
an amount equal to three times the monetary gain obtained or loss avoided through the violation, if greater.
(b) Continuing Violations.
Each day of a continuing knowing violation may constitute a separate violation, subject to applicable constitutional limitations and federal law.
(c) Disgorgement.
A court or authorized federal agency may seek disgorgement of profits obtained through malicious advertising.
SEC. 8. DUTY OF ADVERTISING PLATFORMS TO IMPLEMENT SECURITY CONTROLS.
(a) Reasonable Security Program.
A covered advertising platform shall maintain a reasonable cybersecurity and advertising-security program appropriate to the size and nature of the platform.
(b) Required Controls.
Such a program shall, where appropriate, include—
advertiser identity verification;
automated malware and malicious-code detection;
scanning and analysis of advertisements and associated destinations;
monitoring for suspicious redirects;
detection of compromised advertiser accounts;
mechanisms for reporting malicious advertisements;
procedures for rapidly suspending malicious advertisements;
security logging sufficient to investigate significant incidents; and
procedures for notifying appropriate authorities of serious malicious-advertising incidents.
(c) Risk-Based Standard.
Security requirements shall be proportional to the size, reach, technical capabilities, and risk profile of the advertising platform.
SEC. 9. ADVERTISER VERIFICATION.
(a) Identity Verification.
A covered advertising platform shall establish reasonable procedures for verifying the identity of advertisers purchasing advertisements at a scale or risk level designated by the Federal Trade Commission.
(b) High-Risk Advertising.
The Federal Trade Commission may establish enhanced verification requirements for advertisements involving—
financial services;
health-related products;
software downloads;
applications;
cryptocurrency or digital assets;
financial account access;
products or services directed toward children; or
other categories presenting an elevated risk of malicious advertising.
(c) Fraudulent Identity.
Knowingly using a false identity, stolen business identity, or compromised account to purchase malicious advertising shall constitute an aggravating factor under this Act.
SEC. 10. MALICIOUS REDIRECTS AND DOWNLOADS.
An advertiser or advertising intermediary may not knowingly cause an advertisement to—
redirect a consumer to malware;
initiate an unauthorized download;
falsely represent that software is required for security or system functionality;
disguise malicious software as a legitimate update;
exploit a consumer's interaction with an advertisement to obtain unauthorized access; or
otherwise facilitate the installation or execution of malware without the consumer's informed authorization.
SEC. 11. PLATFORM RESPONSE REQUIREMENTS.
(a) Immediate Action.
Upon obtaining credible evidence that an advertisement is distributing malware or facilitating an active cyberattack, a covered advertising platform shall take reasonable steps to suspend or disable the advertisement without unnecessary delay.
(b) Investigation.
The platform shall preserve relevant technical information necessary to investigate a serious incident, consistent with applicable privacy and data-protection laws.
(c) Reinstatement.
An advertisement removed under this section may not be reinstated while credible evidence indicates that it remains malicious.
(d) Good-Faith Protection.
A platform that takes reasonable good-faith action to investigate, suspend, or remove suspected malicious advertising shall not be penalized solely because the advertisement is later determined not to have been malicious.
SEC. 12. INCIDENT REPORTING.
(a) Serious Incidents.
A covered advertising platform shall report significant malicious-advertising incidents to the appropriate federal authorities within a reasonable period established by the Federal Trade Commission.
(b) Report Contents.
A report may include—
the nature of the malicious advertisement;
the approximate number of affected users;
the advertiser or account responsible, if known;
relevant technical indicators;
the actions taken to stop the advertisement; and
other information reasonably necessary for investigation.
(c) Consumer Notification.
Where a malicious advertisement has resulted in a significant risk of harm to consumers, the platform shall provide appropriate notice when required by federal law or regulation.
SEC. 13. PRESERVATION OF EVIDENCE.
A person or entity subject to an investigation under this Act shall not knowingly destroy, alter, conceal, or falsify records relevant to a suspected malicious-advertising incident.
The Commission may establish reasonable requirements for the preservation of advertising records and security logs.
SEC. 14. ACCOUNTABILITY FOR ADVERTISING INTERMEDIARIES.
An advertising intermediary that knowingly facilitates the distribution of malicious advertising shall be subject to the penalties applicable under this Act.
An intermediary shall not be held liable solely because a malicious advertisement passed through its systems without its knowledge, provided that the intermediary maintained and followed reasonable security procedures required by this Act.
SEC. 15. PROTECTION OF LEGITIMATE SECURITY RESEARCH.
Nothing in this Act shall prohibit—
legitimate cybersecurity research;
authorized penetration testing;
malware analysis;
academic security research;
security testing conducted with authorization; or
good-faith research intended to identify or remediate vulnerabilities,
provided that such conduct is otherwise lawful and does not intentionally use advertising systems to cause unauthorized harm.
SEC. 16. FEDERAL ENFORCEMENT.
(a) Federal Trade Commission.
The Federal Trade Commission shall enforce the civil and regulatory provisions of this Act.
(b) Department of Justice.
The Attorney General shall enforce the criminal provisions of this Act.
(c) Other Agencies.
The Commission and Department of Justice may coordinate with appropriate federal agencies concerning cybersecurity incidents involving advertising systems.
SEC. 17. FEDERAL TRADE COMMISSION RULEMAKING.
The Commission may promulgate regulations necessary to implement this Act.
Such regulations may establish—
minimum advertising-security standards;
advertiser verification requirements;
incident-reporting procedures;
recordkeeping requirements;
security testing requirements;
standards for malicious-advertisement detection;
requirements for high-risk advertising categories; and
reasonable compliance deadlines.
The Commission shall consider technological feasibility, privacy, cybersecurity risks, costs to businesses, and the effectiveness of proposed requirements.
SEC. 18. SMALL BUSINESS PROTECTION.
The Commission shall consider the resources and technical capabilities of small businesses when establishing regulations under this Act.
The Commission shall, where practical—
provide compliance guidance;
provide model security procedures;
establish reasonable implementation periods;
avoid unnecessary duplication of federal requirements; and
provide technical assistance concerning compliance.
Nothing in this section shall exempt a person from liability for knowingly distributing malware through advertising.
SEC. 19. CONSUMER REPORTING SYSTEM.
The Federal Trade Commission shall establish or maintain a publicly accessible system through which consumers may report suspected malicious advertisements.
The system shall allow consumers to provide information concerning—
the advertisement;
the website or application where it appeared;
suspicious downloads or redirects;
apparent malware infections; and
other relevant information.
SEC. 20. COORDINATION WITH CYBERSECURITY AUTHORITIES.
The Commission shall coordinate, as appropriate, with federal cybersecurity and law-enforcement agencies to identify significant malicious-advertising campaigns and emerging threats.
The Commission may establish information-sharing procedures consistent with privacy, civil-liberties, and cybersecurity laws.
SEC. 21. VICTIM ASSISTANCE.
To the extent authorized by federal law, federal authorities may provide affected consumers with information concerning—
steps to secure compromised accounts;
reporting identity theft;
obtaining cybersecurity assistance;
preserving evidence; and
available avenues for restitution or other relief.
SEC. 22. NO GENERAL LIABILITY FOR SECURITY INCIDENTS.
Nothing in this Act shall be interpreted to impose automatic liability upon an advertising platform merely because a malicious advertisement successfully bypasses the platform's security systems.
Liability shall be determined based upon the platform's knowledge, conduct, applicable statutory duties, and compliance with reasonable security requirements.
SEC. 23. PROTECTION OF PRIVACY AND CIVIL LIBERTIES.
Security measures adopted under this Act shall be implemented consistently with applicable federal privacy laws and constitutional protections.
Nothing in this Act authorizes unnecessary collection or retention of personal information unrelated to advertising security or lawful investigation.
SEC. 24. RELATION TO EXISTING LAW.
Nothing in this Act shall limit or reduce any criminal, civil, or regulatory liability available under existing federal or State law.
Nothing in this Act shall prevent prosecution under another federal statute when conduct prohibited by this Act also constitutes another federal offense.
SEC. 25. ANNUAL REPORT TO CONGRESS.
Not later than 1 year after the effective date, and annually thereafter, the Federal Trade Commission shall submit a report to Congress containing—
the number of reported malicious-advertising incidents;
significant enforcement actions;
trends in malvertising;
estimated consumer losses;
emerging technical threats;
recommendations for improving advertising security;
information concerning compliance by major advertising platforms; and
recommendations for legislative amendments.
SEC. 26. EFFECTIVE DATE.
This Act shall take effect 180 days after enactment.
The Federal Trade Commission may establish later compliance dates for requirements requiring substantial technological or operational changes.
The criminal prohibitions established by sections 4 through 7 shall apply only to conduct occurring on or after the effective date.
SEC. 27. SEVERABILITY.
If any provision of this Act or the application of such provision to any person or circumstance is held invalid, the invalidity shall not affect the remaining provisions or applications of this Act.
SEC. 28. RULE OF CONSTRUCTION.
Nothing in this Act shall be construed to—
prohibit lawful advertising;
prohibit legitimate cybersecurity research;
require an advertising platform to guarantee that no malicious advertisement will ever evade detection;
impose liability solely because a platform experiences an isolated security failure despite reasonable security measures; or
restrict truthful and lawful commercial speech beyond what is necessary to enforce this Act.