iNearly half of organizations hit by ransomware attacks end up paying cybercriminals to regain access to their data or systems, while the average ransom demand continues to rise, according to Sophos' 2025 cybersecurity research. As governments move to curb ransom payments, cybersecurity experts remain divided over whether outright bans will reduce cybercrime or create new risks.
Countries are increasingly exploring restrictions on ransom payments. In the UK, the government is progressing plans to prevent public sector organizations and operators of critical national infrastructure—including the National Health Service (NHS), local councils and schools—from paying cybercriminals following ransomware incidents.
The proposed restrictions come as ransomware attacks have become significantly more advanced, with threat actors increasingly targeting vulnerable small and medium-sized businesses through sophisticated techniques.
“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” says Haydn Brooks, chief executive of supply chain security group Risk Ledger. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.”
The rapid adoption of malicious artificial intelligence (AI) tools such as WormGPT, FraudGPT and BruteForceAI has further accelerated ransomware operations. According to Dave Spillane, systems engineering director at Fortinet, confirmed ransomware victims surged by 389% year-on-year in 2025, increasing from nearly 1,600 cases in 2024 to 7,831 worldwide.
“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” he says.
“The cost per attack has dramatically decreased, commoditizing sophisticated attacks, whereas the cost to defend is increasing,” agrees Shashi Kiran, chief marketing officer of tech group Nile. “What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.”
Despite the growing threat, opinions remain sharply divided on whether organizations should ever pay ransom demands.
Jim Walter, senior threat researcher at SentinelOne, believes ransom payments only strengthen cybercriminal operations.
“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he says, warning that cybercriminals cannot be relied upon to permanently delete stolen information after receiving payment.
He further cautions that repeated extortion attempts and continued misuse of stolen data are common outcomes. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.”
However, some experts argue that blanket payment bans fail to account for complex real-world scenarios.
“Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” says Andy Maus, head of cyber recovery services at DriveSavers, a company specializing in hard drive data recovery. “Situations are almost always more nuanced than a ban accounts for.”
For operators of critical national infrastructure, such as water utilities or power providers, prolonged service disruptions could have severe consequences if systems cannot be restored and ransom payments are prohibited.
“We can see how payment bans make sense where data recovery is a viable alternative; however, blanket prohibition has the potential to cause more harm than it prevents,” Maus says.
He also points to previous statewide payment bans introduced in North Carolina and Florida during 2021 and 2022, stating that “neither ban appears to have materially deterred criminal activity.”
Haydn Brooks believes that limiting ransom payments by public institutions could redirect cybercriminal activity toward private businesses.
If public organizations are prohibited from making payments, “the cyber insurance market will inevitably shift,” he adds, “excluding these payouts and driving premiums sky-high as the costs dwarf the original ransom demands.”
As ransomware incidents continue to increase, a growing ecosystem of specialized service providers—including ransom negotiators, incident response teams and breach recovery consultants—is helping organizations evaluate recovery options after attacks.
According to Maus, decisions on whether to pay should consider multiple factors, including the type of data compromised, whether sensitive personal or healthcare information was exposed, and the identity of the threat group behind the attack.
Several cybersecurity experts argue that preventing attacks should take priority over debating ransom payments.
Gavin Millard, vice-president of product at Tenable, believes the primary focus should be on reducing ransomware profitability by strengthening organizations' security posture. He notes that many attacks continue to exploit known vulnerabilities, exposed systems and existing security gaps, making exposure management a critical defense strategy.
Walter also stresses the importance of maintaining strong cybersecurity practices, including continuous device monitoring and mandatory multi-factor authentication.
“What you really need is visibility over access to internal systems, and the ability to limit impact once they’re inside,” says Spencer Young, international senior vice-president at access management company Delinea. “Strong controls—like giving employees temporary, on-the-spot permission only when needed—shrink the blast radius and stop ransomware actors from achieving their goals.”
Meanwhile, Maus believes governments should focus on proactive cybersecurity investments instead of relying solely on payment bans.
Rather than prohibiting organizations from paying after an attack occurs, he argues that subsidizing secure backup infrastructure and offering tax incentives for cybersecurity investments “would do more to reduce the underlying exposure.”