23.4 C
London
Tuesday, July 21, 2026
Home ransomware Pay up or not? Ransomware surge has victims facing tough choices.
pay-up-or-not?-ransomware-surge-has-victims-facing-tough-choices.
Pay up or not? Ransomware surge has victims facing tough choices.

Pay up or not? Ransomware surge has victims facing tough choices.

4
0

Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising.

Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for example, the government is advancing plans to prohibit public sector bodies and critical national infrastructure groups—including the National Health Service, local councils and schools—from making payouts.

The potential veto comes as ransomware hackers have become more advanced and meticulous in their targeting of companies, particularly vulnerable small and medium-sized businesses, over time.

“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” says Haydn Brooks, chief executive of supply chain security group Risk Ledger. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.”

This has been powered by the rise of malicious AI hacking tools such as WormGPT, FraudGPT and BruteForceAI, according to Dave Spillane, systems engineering director at Fortinet, who notes that confirmed ransomware victims rose 389 percent year-on-year in 2025, from around 1,600 in 2024 to 7,831 globally.

“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” he says.

“The cost per attack has dramatically decreased, commoditizing sophisticated attacks, whereas the cost to defend is increasing,” agrees Shashi Kiran, chief marketing officer of tech group Nile. “What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.”

Nevertheless, whether to pay out or not remains one of the most divisive areas in cybersecurity.

Jim Walter, a senior threat researcher at SentinelOne, says that his cyber security group takes a hard line against responding to ransoms.

“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he says, noting that threat actors cannot be trusted to delete data upon payment.

Re-extortion and the ongoing monetization of stolen data are commonplace, he adds. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.”

Others are less absolute. “Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” says Andy Maus, head of cyber recovery services at DriveSavers, which recovers hard drive data. “Situations are almost always more nuanced than a ban accounts for.”

When it comes to critical national infrastructure, for example, such as a water utility or power provider, the consequences for customers can be more serious if a ransom cannot be paid but data also cannot be recovered. “We can see how payment bans make sense where data recovery is a viable alternative; however, blanket prohibition has the potential to cause more harm than it prevents,” Maus says.

He notes that in North Carolina and Florida, where statewide bans were introduced in 2021 and 2022 respectively, “neither ban appears to have materially deterred criminal activity.”

Brooks at Risk Ledger warns that without critical national infrastructure payouts, cyber criminals will “aggressively pivot” to the more unregulated private sector.

If public bodies are banned from paying, “the cyber insurance market will inevitably shift,” he adds, “excluding these payouts and driving premiums sky-high as the costs dwarf the original ransom demands.”

There is now a growing market of services to support companies in their response to attacks, including ransom negotiators, incident response teams and breach coaches that assess data recovery options.

Maus argues that details such as what data was stolen, whether it involves personally identifiable or sensitive health information, and which threat group is responsible, should all be part of weighing whether data recovery is viable or payment is the right option.

But instead of whether to ban payments or not, “the more important question is how to make ransomware less profitable in the first place,” says Gavin Millard, vice-president of product at cyber security company Tenable. Most ransomware attacks still rely on familiar problems such as known vulnerabilities, exposed systems and security gaps, he adds, and the focus should therefore be “exposure management.”

Walter at SentinelOne says companies need an “awareness of emerging trends in the threat landscape alongside proper technical hygiene” including the continuous monitoring of devices and enforced multi-factor authentication.

“What you really need is visibility over access to internal systems, and the ability to limit impact once they’re inside,” says Spencer Young , international senior vice-president at access management group Delinea. “Strong controls—like giving employees temporary, on-the-spot permission only when needed—shrink the blast radius and stop ransomware actors from achieving their goals.”

Others are calling for more innovative support from governments.

Rather than prohibiting payment for an attack that has already happened, DriveSavers’ Maus says investing in subsidized backup infrastructure or tax incentives for cybersecurity spending “would do more to reduce the underlying exposure.”

© 2026 The Financial Times Ltd. All rights reserved. Not to be redistributed, copied, or modified in any way.