
U.K. plans to block ransomware payments from public bodies as attacks jumped 389% in a year. Security experts split on whether a ban would reduce extortion or leave victims with no recovery path.
Governments including the U.K. are moving toward banning ransomware payments, a shift that pits public-sector security against a hacker ecosystem that has grown more efficient and harder to track.
The U.K. plans to block ransomware payouts from public sector organizations and critical national infrastructure groups, the Financial Times reported Monday. The proposal comes as confirmed ransomware victims surged from 1,600 in 2024 to 7,831 in 2025, a 389% jump, according to Dave Spillane, systems engineering director at Fortinet.
"In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously," Spillane told the FT.
The rise is tied to AI hacking tools that let attackers automate reconnaissance and deployment. Haydn Brooks, chief executive of supply chain security group Risk Ledger, described the current environment as a "highly sophisticated, corporate-style ecosystem" where ransomware groups operate like smart B2B operations to ensure data return. The legal and sanction risks of paying, Brooks said, are at an all-time high.
The debate over whether to pay remains unresolved.
Jim Walter, a senior threat researcher at SentinelOne, said his company opposes responding to ransoms. "Paying extortive threat actors only strengthens the ecosystem and the entities that enable it," he said, adding that there is no guarantee hackers will delete data upon payment. "Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion."
Andy Maus, head of cyber recovery services at DriveSavers, offered a different view. "Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible," Maus said. "Situations are almost always more nuanced than a ban accounts for."
For companies facing a ransomware demand, the immediate decision turns on whether they can restore operations from backups. If backups are intact and recent, the calculus leans against paying. If critical data is encrypted and unrecoverable, the ban could force a binary choice between permanent data loss and breaking the law.
The U.K. proposal targets public bodies and critical infrastructure operators first. A broader ban covering private companies would face heavier resistance from businesses that see payment as the only viable recovery path.
No timeline for the U.K. ban has been set.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.