

Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising.
Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for example, the government is advancing plans to prohibit public sector bodies and critical national infrastructure groups—including the National Health Service, local councils and schools—from making payouts.
The potential veto comes as ransomware hackers have become more advanced and meticulous in their targeting of companies, particularly vulnerable small and medium-sized businesses, over time.
“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” says Haydn Brooks, chief executive of supply chain security group Risk Ledger. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.”
This has been powered by the rise of malicious AI hacking tools such as WormGPT, FraudGPT and BruteForceAI, according to Dave Spillane, systems engineering director at Fortinet, who notes that confirmed ransomware victims rose 389 percent year-on-year in 2025, from around 1,600 in 2024 to 7,831 globally.
“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” he says.
“The cost per attack has dramatically decreased, commoditizing sophisticated attacks, whereas the cost to defend is increasing,” agrees Shashi Kiran, chief marketing officer of tech group Nile. “What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.”
Nevertheless, whether to pay out or not remains one of the most divisive areas in cybersecurity.
Jim Walter, a senior threat researcher at SentinelOne, says that his cyber security group takes a hard line against responding to ransoms.
“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he says, noting that threat actors cannot be trusted to delete data upon payment.
Re-extortion and the ongoing monetization of stolen data are commonplace, he adds. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.”
Others are less absolute. “Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” says Andy Maus, head of cyber recovery services at DriveSavers, which recovers hard drive data. “Situations are almost always more nuanced than a ban accounts for.”







