Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label AI-powered cyberattacks. Show all posts

Ransomware Attacks Become More Sophisticated as Experts Debate Effectiveness of Payment Bans

 

iNearly half of organizations hit by ransomware attacks end up paying cybercriminals to regain access to their data or systems, while the average ransom demand continues to rise, according to Sophos' 2025 cybersecurity research. As governments move to curb ransom payments, cybersecurity experts remain divided over whether outright bans will reduce cybercrime or create new risks.

Countries are increasingly exploring restrictions on ransom payments. In the UK, the government is progressing plans to prevent public sector organizations and operators of critical national infrastructure—including the National Health Service (NHS), local councils and schools—from paying cybercriminals following ransomware incidents.

The proposed restrictions come as ransomware attacks have become significantly more advanced, with threat actors increasingly targeting vulnerable small and medium-sized businesses through sophisticated techniques.

“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” says Haydn Brooks, chief executive of supply chain security group Risk Ledger. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.”

The rapid adoption of malicious artificial intelligence (AI) tools such as WormGPT, FraudGPT and BruteForceAI has further accelerated ransomware operations. According to Dave Spillane, systems engineering director at Fortinet, confirmed ransomware victims surged by 389% year-on-year in 2025, increasing from nearly 1,600 cases in 2024 to 7,831 worldwide.

“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” he says.

“The cost per attack has dramatically decreased, commoditizing sophisticated attacks, whereas the cost to defend is increasing,” agrees Shashi Kiran, chief marketing officer of tech group Nile. “What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.”

Despite the growing threat, opinions remain sharply divided on whether organizations should ever pay ransom demands.

Jim Walter, senior threat researcher at SentinelOne, believes ransom payments only strengthen cybercriminal operations.

“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he says, warning that cybercriminals cannot be relied upon to permanently delete stolen information after receiving payment.

He further cautions that repeated extortion attempts and continued misuse of stolen data are common outcomes. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.”

However, some experts argue that blanket payment bans fail to account for complex real-world scenarios.

“Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” says Andy Maus, head of cyber recovery services at DriveSavers, a company specializing in hard drive data recovery. “Situations are almost always more nuanced than a ban accounts for.”

For operators of critical national infrastructure, such as water utilities or power providers, prolonged service disruptions could have severe consequences if systems cannot be restored and ransom payments are prohibited.

“We can see how payment bans make sense where data recovery is a viable alternative; however, blanket prohibition has the potential to cause more harm than it prevents,” Maus says.

He also points to previous statewide payment bans introduced in North Carolina and Florida during 2021 and 2022, stating that “neither ban appears to have materially deterred criminal activity.”

Haydn Brooks believes that limiting ransom payments by public institutions could redirect cybercriminal activity toward private businesses.

If public organizations are prohibited from making payments, “the cyber insurance market will inevitably shift,” he adds, “excluding these payouts and driving premiums sky-high as the costs dwarf the original ransom demands.”

As ransomware incidents continue to increase, a growing ecosystem of specialized service providers—including ransom negotiators, incident response teams and breach recovery consultants—is helping organizations evaluate recovery options after attacks.

According to Maus, decisions on whether to pay should consider multiple factors, including the type of data compromised, whether sensitive personal or healthcare information was exposed, and the identity of the threat group behind the attack.

Several cybersecurity experts argue that preventing attacks should take priority over debating ransom payments.

Gavin Millard, vice-president of product at Tenable, believes the primary focus should be on reducing ransomware profitability by strengthening organizations' security posture. He notes that many attacks continue to exploit known vulnerabilities, exposed systems and existing security gaps, making exposure management a critical defense strategy.

Walter also stresses the importance of maintaining strong cybersecurity practices, including continuous device monitoring and mandatory multi-factor authentication.

“What you really need is visibility over access to internal systems, and the ability to limit impact once they’re inside,” says Spencer Young, international senior vice-president at access management company Delinea. “Strong controls—like giving employees temporary, on-the-spot permission only when needed—shrink the blast radius and stop ransomware actors from achieving their goals.”

Meanwhile, Maus believes governments should focus on proactive cybersecurity investments instead of relying solely on payment bans.

Rather than prohibiting organizations from paying after an attack occurs, he argues that subsidizing secure backup infrastructure and offering tax incentives for cybersecurity investments “would do more to reduce the underlying exposure.”

Cybercriminals Harness AI and Automation, Leaving Southeast Asia Exposed

 

A new study warns that cybercriminals are leveraging artificial intelligence (AI) and automation to strike faster and with greater precision, exposing critical weaknesses in Southeast Asia—a region marked by rapid digital growth and interconnected supply chains. The findings urge businesses to treat cybersecurity as the foundation of digital trust and organizational resilience.

The report highlights a significant surge in sophisticated, multi-layered attacks targeting global enterprises, with Southeast Asia among the most vulnerable. Nearly 70% of breaches involved attackers using at least three entry points simultaneously—ranging from web browsers and cloud applications to networks and human behavior. Alarmingly, 44% of these incidents began with browser-based exploits, taking advantage of everyday workplace tools like file-sharing services and collaboration platforms. Researchers caution that disconnected and siloed security solutions cannot keep pace with attackers who seamlessly move across fragmented IT environments. To counter this, organizations must implement integrated, real-time protection across cloud, endpoint, identity, and network layers.

Phishing has returned as the top method of unauthorized access, responsible for 23% of incidents in 2024. What sets this new wave apart is the use of generative AI, allowing cybercriminals to create convincing phishing campaigns that mimic professional communication styles, workflows, and even individual employee voices. Experts emphasize that traditional once-a-year security training is no longer sufficient. Instead, businesses must adopt continuous, behavior-based awareness programs alongside AI-driven detection tools that monitor anomalies across emails, messaging platforms, and user activities. The goal is to create a dynamic “human firewall” where people and machines work in tandem against evolving threats.

The study also reveals a troubling rise in insider-driven breaches, which tripled in 2024. Nation-state groups—most notably from North Korea—successfully infiltrated companies by posing as job applicants, even using deepfake video interviews convincing enough to secure technical roles and gain insider access. Traditional security measures often fail against attackers disguised as legitimate users. To address this, experts recommend adopting zero-trust frameworks that enforce least-privilege access, continuous verification, and ongoing behavioral monitoring. The report stresses that “trust cannot be assumed; it must be continuously validated.”

Perhaps the most alarming discovery is the accelerated pace of cyber incidents. Data theft, which once took days, now unfolds within hours—sometimes less than one. In 2024, one in four breaches involved data exfiltration within five hours of initial compromise, with some completed in under an hour. Automation and AI have drastically shortened the attacker’s kill chain. The only effective defense, the report notes, is speed: leveraging automated triage, unified threat intelligence, and AI-powered response mechanisms to prevent security teams from lagging behind.

For ASEAN economies—where cloud adoption, cross-border data sharing, and sprawling supply chains intersect—the risks are especially high. The report urges regional leaders to view cybersecurity as a strategic priority, directly linked to resilience and long-term trust. “The most damaging breaches stem from too much complexity, too little visibility, and too much trust,” the report concludes. By embedding security from code to cloud, simplifying operations through automation, and embracing threat-informed strategies, Southeast Asian businesses can turn vulnerabilities into resilience