Advertisement
Advertisement
Advertisement
20 July 2026ยท5 min readยทBy Sloane Meyer

Ransomware Attacks: Should You Ever Pay?

With ransomware attacks rising, experts debate whether paying hackers is worth it or if it just encourages future crime.

Ransomware Attacks: Should You Ever Pay?

It's a losing move either way. Ransomware attacks force victims into a corner where nearly half of the businesses hit by these digital kidnappers decide to pay the ransom to regain their data. But handing over money isn't just a financial transaction. It's a gamble. There's no guarantee of recovery at all.

The Rising Cost of Digital Extortion

The numbers are staggering. It's a sharp spike, and globally, the count of confirmed victims jumped from 1,600 in 2024 to 7,831 in 2025 , a 389 percent increase that shows how quickly the threat is growing. Hackers are using automated tools like WormGPT, FraudGPT, and BruteForceAI to scale their operations. So they're not just targeting one company at a time anymore. They can now hit four organizations at once.

But the barrier to entry for cyber criminals has dropped significantly. It's creating a vicious cycle that lets criminals operate with high efficiency while victims struggle to keep up, and this problem is only getting worse. Defending against these threats costs more every year. So they're winning.

The Debate Over Paying Up

Should you ever pay? Security experts are divided. Some argue that paying only feeds the cycle of crime, so it's a bad idea that encourages more attacks and makes the problem worse for everyone. But others point out that if your critical systems are locked, you might have no other choice.

Paying extortive threat actors only strengthens the ecosystem and the entities that enable it. Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.

Criminals can't be trusted. Jim Walter, a senior threat researcher at SentinelOne, explains that paying criminals is dangerous because they often demand more money or continue to sell stolen data even after a payment is made. But others argue that bans on payments ignore the reality of a crisis.

Market Context: According to Illumio's Global Cost of Ransomware Report, only 13% of victims recovered all encrypted data after paying the ransom in 2024, with 40% reporting data leaks and 32% facing further demands or threats.

When Bans Do More Harm

Government bodies are exploring total bans on ransomware payments. But some experts worry these policies are too rigid and might cause more harm than good, especially since the UK is currently moving to stop public sector groups and critical infrastructure from paying ransoms. It's a risky bet.

person using black laptop computer on brown wooden table
  • Public sector bodies in the UK face new payment bans.
  • Statewide bans in North Carolina and Florida failed to deter criminal activity.
  • Banning payments may force hackers to target the private sector instead.
  • Cyber insurance premiums may soar if payouts are excluded from coverage.

Andy Maus, head of cyber recovery services at DriveSavers, suggests that blanket bans might cause more damage than they prevent. Context matters. So if a water utility can't recover data and is forbidden from paying to unlock it, the public suffers, and that's why each situation is nuanced and a one-size-fits-all ban rarely accounts for the complexity of a total system lockout.

Stopping the Profit Motive

Stop chasing the ransom. Security leaders argue we should shift from banning payments to simply making these attacks less profitable, a strategy that forces attackers to work harder and find fewer easy targets. Close the gaps before hackers find them.

Improving Your Technical Hygiene

Technical hygiene is your first line of defense. You must monitor your devices continuously. Enforce multi-factor authentication everywhere. If you provide your employees with temporary, on-the-spot permissions, you limit what a hacker can touch if they manage to get inside your network.

Investing in True Resilience

Stop hoping you won't be a target. Governments should look into subsidizing backup infrastructure instead of just banning payouts, and tax incentives for security spending could encourage companies to harden their systems. But you need visibility over your internal access points. Shrink your blast radius now. It's the only way to stop a breach from becoming a disaster.

The Path Forward

The era of corporate-style ransomware is here. Hackers are acting like smart business operators, systematically targeting small and medium-sized businesses because they know you can't afford to stay down for long. Don't wait for a ransom note to think about your security. Assume the perimeter will be breached. Plan your recovery before the systems go dark, and remember that the best way to deal with a ransom is to make sure you never have to pay one. So do it now.

Frequently Asked Questions

What does the article say about the likelihood of data recovery after paying a ransom in ransomware attacks?

The article states that paying a ransom is a gamble with no guarantee of recovery. It notes that paying absolutely does not guarantee recovery and can encourage further crime and extortion.

Why are some security experts opposed to paying ransoms in ransomware attacks?

Some experts argue that paying only feeds the cycle of crime, encourages more attacks, and makes the problem worse for everyone. Jim Walter explains that criminals often demand more money or continue to sell stolen data even after payment.

How did the number of confirmed ransomware victims change from 2024 to 2025 according to the article?

The article reports that globally, the count of confirmed victims jumped from 1,600 in 2024 to 7,831 in 2025. This represents a 389 percent increase, showing how quickly the threat is growing.

What technical measures does the article recommend to defend against ransomware attacks?

The article recommends continuous device monitoring, enforcing multi-factor authentication everywhere, and providing employees with temporary on-the-spot permissions to limit what hackers can access. These steps improve technical hygiene and shrink the blast radius.

Who is Andy Maus and what is his view on blanket bans of ransomware payments?

Andy Maus is the head of cyber recovery services at DriveSavers. He suggests that blanket bans might cause more damage than they prevent, arguing that context matters and a one-size-fits-all ban rarely accounts for the complexity of a total system lockout.

Sloane Meyer
Written by
Cybersecurity Editor

Sloane Meyer covers cybersecurity, privacy and the threats facing individuals and organisations online. She explains how attacks happen and what can be done to stay protected.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement