Key facts
- Nearly half of companies targeted by ransomware pay the ransom.
- The median ransom demand is increasing globally.
- Governments are exploring bans on ransom payments for public sector bodies and critical national infrastructure.
- AI tools like WormGPT and FraudGPT are making ransomware attacks more sophisticated and faster.
- Confirmed ransomware victims increased by 389% year-on-year in 2025.
- Experts are divided on the efficacy of ransom payment bans, with some arguing they could harm critical services and others advocating for them to disrupt the ransomware ecosystem.
Ransomware attacks are becoming increasingly sophisticated, driven by AI-powered tools, leading to a surge in victims and forcing difficult decisions about whether to pay ransoms. Globally, governments are considering or implementing bans on such payments, particularly for public sector entities and critical national infrastructure. However, experts are divided on the effectiveness and implications of these bans.
According to 2025 research from cyber security group Sophos, nearly half of companies targeted by ransomware end up paying, with the median ransom demand on the rise. In the UK, plans are advancing to prohibit public sector bodies, including the NHS, local councils, and schools, from making payouts. This move comes as ransomware hackers have evolved into a "highly sophisticated, corporate-style ecosystem," operating like businesses to ensure data return, according to Haydn Brooks, CEO of Risk Ledger. He notes that while these groups operate efficiently, the legal and sanction risks of paying are at an all-time high.
The rise of malicious AI hacking tools such as WormGPT, FraudGPT, and BruteForceAI has dramatically increased the speed and volume of attacks. Dave Spillane, systems engineering director at Fortinet, reported that confirmed ransomware victims rose 389% year-on-year in 2025, from approximately 1,600 in 2024 to 7,831 globally. "In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously," Spillane stated. Shashi Kiran, CMO of Nile, agreed that the cost to defend is increasing while the cost per attack has decreased, making sophisticated attacks accessible to individuals with limited skills.
Despite the increasing sophistication, the question of whether to pay remains divisive. Jim Walter, a senior threat researcher at SentinelOne, advocates for a strict stance against paying ransoms, arguing that it strengthens the ransomware ecosystem and that threat actors cannot be trusted to delete data upon payment. He emphasizes that paying does not guarantee data recovery and encourages further crime.
Others, like Andy Maus, head of cyber recovery services at DriveSavers, express concern about payment bans when data recovery is not feasible. Maus argues that situations are often more nuanced than a ban allows for, especially for critical infrastructure like water or power providers, where failure to recover data could have severe consequences for customers. He points to North Carolina and Florida, where statewide bans introduced in 2021 and 2022 respectively, do not appear to have materially deterred criminal activity.
Brooks of Risk Ledger warns that if public bodies are banned from paying, cyber criminals will "aggressively pivot" to the less regulated private sector. This shift could also impact the cyber insurance market, potentially driving premiums higher as costs exceed original ransom demands. The market now offers services like ransom negotiators and incident response teams to support companies. Maus suggests that factors such as the type of data stolen (personally identifiable or sensitive health information) and the responsible threat group should influence decisions on payment versus recovery.
Gavin Millard, vice-president of product at Tenable, suggests that the more critical question is how to make ransomware less profitable. He notes that most attacks exploit familiar vulnerabilities and security gaps, highlighting the importance of "exposure management." Walter at SentinelOne stresses the need for companies to be aware of emerging threats and maintain proper technical hygiene, including continuous device monitoring and multi-factor authentication. Spencer Young of Delinea emphasizes visibility over internal systems and limiting access to shrink the "blast radius" of attacks.
Some experts advocate for innovative government support, such as investing in subsidized backup infrastructure or offering tax incentives for cybersecurity spending, as more effective measures to reduce underlying exposure than prohibiting payments after an attack has occurred.
