Ransomware attacks have become increasingly sophisticated, with confirmed victims rising 389 percent year-on-year in 2025, from approximately 1,600 in 2024 to 7,831 globally. This surge is attributed to the rise of malicious AI hacking tools like WormGPT, FraudGPT, and BruteForceAI, which have dramatically decreased the cost per attack and commoditized sophisticated cyber crimes. While previously requiring nation-state resources, individuals with limited skills can now execute complex attacks. Nearly half of targeted companies end up paying ransoms, and the median demand is rising.
Governments are responding to this trend with varying approaches. The UK, for instance, is considering banning ransom payments for public sector bodies and critical national infrastructure groups. However, some argue that blanket prohibitions could cause more harm than good, particularly when data recovery isn't feasible. Examples from North Carolina and Florida, which introduced statewide bans in 2021 and 2022 respectively, show no material deterrence of criminal activity. Critics like Andy Maus of DriveSavers emphasize that situations are often more nuanced than a simple ban allows, advocating for subsidized backup infrastructure and tax incentives for cybersecurity spending instead.
There's a significant divide within the cybersecurity community on the payment issue. Jim Walter, a senior threat researcher at SentinelOne, takes a firm stance against paying, arguing it emboldens attackers and doesn't guarantee data deletion, often leading to re-extortion. Conversely, Gavin Millard of Tenable suggests focusing on making ransomware less profitable by addressing common vulnerabilities and systems exposures. He highlights that most attacks still exploit known weaknesses. Risk Ledger's CEO, Haydn Brooks, warns that public sector payment bans would likely cause criminals to aggressively target the unregulated private sector, potentially driving up cyber insurance premiums.
The debate also covers the practicalities of recovery and prevention. While a growing market offers services like ransom negotiators and incident response teams, experts stress the importance of robust cybersecurity measures. These include continuous device monitoring, enforced multi-factor authentication, and sophisticated access management systems that limit the impact of a breach. Ultimately, the decision to pay often depends on factors like the type of data stolen (e.g., personally identifiable or sensitive health information) and the specific threat group involved.