Ransomware victims are being squeezed between criminals who have scaled up their operations and governments that increasingly want to block payments. Sophos research from 2025 found that close to half of companies hit by ransomware paid to regain access to data or systems, while the typical demand was climbing.
The UK government is advancing plans to bar public-sector organizations and critical national infrastructure operators from paying hackers. The proposed ban would cover bodies including the National Health Service, local councils and schools. Similar restrictions already exist in some places, including statewide bans in North Carolina and Florida introduced in 2021 and 2022, according to Andy Maus, head of cyber recovery services at DriveSavers.
The policy fight is landing as attackers get more selective and more industrial. Haydn Brooks, chief executive of supply-chain security company Risk Ledger, said ransomware crews in 2026 resemble business-to-business operations, with processes built around getting paid and returning data. He also warned that victims face higher legal and sanctions risks when they pay.
Dave Spillane, systems engineering director at Fortinet, attributed part of the surge to malicious AI tools such as WormGPT, FraudGPT and BruteForceAI. Fortinet counted 7,831 confirmed ransomware victims globally in 2025, up from about 1,600 in 2024, a 389 percent increase. Spillane said automation lets attackers hit several organizations in the time previously needed for one.
Shashi Kiran, chief marketing officer at Nile, made the same basic point from the economics side: the cost of launching sophisticated attacks has fallen, while the cost of defending against them has risen. He said capabilities once associated with nation-state operators can now be used by individuals with weaker skills and AI assistance. That is bad news for small and midsize businesses, which often lack the staff, backups and monitoring needed to absorb an intrusion without blinking.
Security companies are split on whether bans help. Jim Walter, a senior threat researcher at SentinelOne, said his company opposes ransom payments. In his view, paying funds the criminal market and does not make attackers reliable custodians of stolen data. Walter said victims can still face repeat extortion or later abuse of the same stolen material after payment.
Maus argued that blanket bans can ignore the ugly operational details. If a water utility, power provider or hospital cannot recover data and also cannot pay, the harm can land on customers and patients, not just the breached organization. He said the North Carolina and Florida bans do not appear to have meaningfully discouraged criminal activity.
Brooks warned that if public bodies and infrastructure operators are removed from the payment pool, attackers may shift toward less-regulated private companies. He also said cyber insurers could respond by excluding ransom coverage for banned entities and raising premiums when recovery costs exceed the original demand.
A cottage industry has grown around these decisions: ransom negotiators, incident response teams and breach coaches now help companies assess whether data can be restored and what exposure follows from a leak. Maus said factors such as the type of stolen data, the presence of health or personal information, and the identity of the criminal group should shape any recovery decision.
Several security executives said the better lever is prevention. Gavin Millard, vice-president of product at Tenable, said ransomware still commonly depends on known flaws, exposed systems and gaps in basic controls. Walter called for continuous device monitoring and enforced multi-factor authentication. Spencer Young, international senior vice-president at Delinea, said companies need tighter visibility into internal access and temporary, limited permissions so intruders cannot roam freely once inside.
Maus said governments could reduce exposure more directly by subsidizing backup infrastructure or offering tax incentives for cybersecurity spending. That would be less theatrical than banning ransom payments after the breach, but it would also target the boring failure modes ransomware crews keep monetizing.
This story draws on original reporting from Ars Technica.