Key facts
- Nearly half of companies targeted by ransomware pay the ransom.
- The median ransom demand is increasing globally.
- Governments are exploring bans on ransom payments for public sector bodies and critical national infrastructure.
- AI tools like WormGPT and FraudGPT are making ransomware attacks more sophisticated and faster.
- Confirmed ransomware victims increased by 389% year-on-year in 2025.
- Experts are divided on the efficacy of ransom payment bans, with some arguing they could harm critical services and others advocating for them to disrupt the ransomware ecosystem.
Ransomware attacks are becoming increasingly sophisticated, driven by AI-powered tools, leading to a surge in victims and forcing difficult decisions about whether to pay ransoms. Globally, governments are considering or implementing bans on such payments, particularly for public sector entities and critical national infrastructure. However, experts are divided on the effectiveness and implications of these bans.
According to 2025 research from cyber security group Sophos, nearly half of companies targeted by ransomware end up paying, with the median ransom demand on the rise. In the UK, plans are advancing to prohibit public sector bodies, including the NHS, local councils, and schools, from making payouts. This move comes as ransomware hackers have evolved into a "highly sophisticated, corporate-style ecosystem," operating like businesses to ensure data return, according to Haydn Brooks, CEO of Risk Ledger. He notes that while these groups operate efficiently, the legal and sanction risks of paying are at an all-time high.
The rise of malicious AI hacking tools such as WormGPT, FraudGPT, and BruteForceAI has dramatically increased the speed and volume of attacks. Dave Spillane, systems engineering director at Fortinet, reported that confirmed ransomware victims rose 389% year-on-year in 2025, from approximately 1,600 in 2024 to 7,831 globally. "In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously," Spillane stated. Shashi Kiran, CMO of Nile, agreed that the cost to defend is increasing while the cost per attack has decreased, making sophisticated attacks accessible to individuals with limited skills.
