Pay up or not? Ransomware surge has victims facing tough choices

← Back to the feed

Pay up or not? Ransomware surge has victims facing tough choices

Ars Technica · 20 hours ago

Ransomware attacks are surging and becoming more sophisticated, forcing an increasing number of victims into a difficult choice between paying hackers or refusing and risking permanent data loss. Nearly half of targeted companies now pay a ransom, according to 2025 research from Sophos, and the UK government is advancing plans to ban public sector bodies and critical national infrastructure organisations, including the NHS, councils and schools, from making such payments. The trend matters because it pits efforts to starve criminal networks of funding against the practical reality that some victims, particularly those running essential services, may have no viable way to recover their data without paying.

Experts point to AI-powered hacking tools such as WormGPT, FraudGPT and BruteForceAI as a key driver, with Fortinet reporting a 389% year-on-year rise in confirmed ransomware victims in 2025, from around 1,600 to 7,831 globally. Security specialists remain divided on payment bans: some, like SentinelOne's Jim Walter, argue paying only emboldens attackers and rarely guarantees safe data recovery, while others, such as DriveSavers' Andy Maus, warn that blanket bans can cause more harm when recovery isn't feasible, noting that existing state-level bans in North Carolina and Florida have not visibly deterred criminal activity. Risk Ledger's Haydn Brooks cautioned that restricting public sector payouts could push criminals towards less-regulated private firms and drive up cyber insurance premiums.

  • Ransomware attacks rose 389% year-on-year in 2025, fuelled by AI hacking tools.
  • UK plans to ban public bodies and NHS from paying ransoms.
  • Experts split: bans may deter crime or worsen outcomes when recovery isn't possible.

Cybersecurity Government Politics Technology

Read the full article at the source →