Nearly half of targeted companies pay ransoms amid rising demands, according to 2025 data. Governments including the UK are advancing bans on payments by public sector bodies and critical infrastructure. Experts debate whether such prohibitions help or harm recovery efforts.
Research from Sophos shows almost 50 percent of ransomware victims pay to regain access, with median demands increasing. Confirmed global victims jumped 389 percent year-on-year to 7,831 in 2025.
The UK government is advancing plans to ban payouts by public bodies such as the National Health Service, local councils and schools. Similar statewide bans in North Carolina and Florida since 2021 and 2022 have not deterred attacks.
Experts note that AI tools like WormGPT have cut attack costs and allowed hackers to target multiple organizations at once. Some warn that bans could push criminals toward unregulated private firms and raise insurance premiums.
Others stress exposure management, multi-factor authentication and visibility controls over systems as better long-term defenses. Recovery specialists say decisions should weigh data sensitivity and feasibility of alternatives rather than blanket rules.