Technology

Ransomware payment bans face scrutiny as attacks rise

Governments are weighing bans on ransom payments as AI-assisted attacks spread, but security experts disagree on whether prohibition reduces harm.

Maya Lindqvist

By Maya Lindqvist · Senior Technology Correspondent

3 min read

Ransomware payment bans face scrutiny as attacks rise
Photo: Ars Technica

Ransomware victims are facing harder choices as attacks grow more common and payment demands climb. Sophos research from 2025 found that nearly half of targeted companies paid to regain access to data or systems, while security specialists say attackers have become more selective and efficient.

Some governments are responding by trying to cut off the money. In the UK, ministers are advancing plans to bar public-sector bodies and critical national infrastructure operators from paying hackers, including the National Health Service, local councils and schools.

The debate has sharpened as ransomware groups have become more organized. Haydn Brooks, chief executive of supply-chain security company Risk Ledger, said ransomware in 2026 has developed into a sophisticated, businesslike criminal market. He said payment now carries heightened legal and sanctions risks even as some gangs present themselves as reliable enough to return data after being paid.

Dave Spillane, systems engineering director at Fortinet, linked the acceleration to malicious AI tools including WormGPT, FraudGPT and BruteForceAI. He said confirmed ransomware victims rose 389% year on year in 2025, from about 1,600 in 2024 to 7,831 worldwide.

Spillane said attackers can now hit four organizations in the time previously needed for one attack. Shashi Kiran, chief marketing officer at Nile, said AI has lowered the cost of attacks and put techniques once associated with nation states within reach of less skilled criminals.

Security experts split over paying

Many cyber specialists oppose ransom payments because they fund more crime. Jim Walter, a senior threat researcher at SentinelOne, said paying extortionists strengthens the criminal networks behind ransomware and does not ensure stolen information will be deleted.

Walter said re-extortion and continued attempts to profit from stolen data are common. He argued that payment does not guarantee a recovery and encourages further attacks.

Others warn that a strict ban can create difficult consequences when a victim cannot restore data. Andy Maus, head of cyber recovery services at DriveSavers, said bans may fail to account for cases where recovery is not possible and a disrupted service affects the public.

Maus pointed to critical infrastructure such as water or power providers, where prolonged outages can affect customers. He said payment bans may be easier to justify when recovery is available, but broad prohibitions can create risks of their own.

He also cited statewide bans introduced in North Carolina in 2021 and Florida in 2022, saying neither appears to have significantly discouraged criminal activity. Brooks warned that if critical infrastructure operators stop paying, criminals may shift more aggressively toward less regulated private-sector targets.

Brooks said a ban on public bodies could also affect cyber insurance, with insurers excluding those payments and premiums rising as recovery costs exceed original ransom demands.

Prevention remains the focus

A growing industry now supports companies after attacks, including ransom negotiators, incident response teams and breach coaches. Maus said any decision should consider the kind of data stolen, whether it includes personal or health information, and which criminal group is involved.

Gavin Millard, vice-president of product at Tenable, said the main goal should be making ransomware less profitable. He said many attacks still depend on known vulnerabilities, exposed systems and security gaps, making exposure management a priority.

Walter said companies need to track emerging threats while maintaining strong technical practices, including continuous device monitoring and enforced multi-factor authentication. Spencer Young, international senior vice-president at Delinea, said organizations also need tighter control over access to internal systems so attackers have less room to move once inside.

Maus said governments could reduce risk by supporting backup systems or offering tax incentives for cybersecurity spending, rather than focusing only on whether victims may pay after an attack has already occurred.

This story draws on original reporting from Ars Technica.