As Ransomware Blackmail Surges, Governments Mull a Ban on Paying Up
Ransomware attacks on small and medium-sized businesses have surged over the past two years, prompting some governments to begin investigating a ban on paying up for data recovery, Ars Technica reports. Although the evidence suggests that paying up just emboldens attackers, for affected companies with no clear alternative, it’s often the more attractive option.
Ransomware has been a problem for businesses and individuals for years, but with the growth of AI hacking tools like WormGPT, FraudGPT, and BruteForceAI, ransomware is becoming more pervasive and harder to stop. The use of AI tools makes ransomware attacks faster and cheaper to conduct, increasing the return on investment and making it a more attractive vector for hackers.
Confirmed ransomware attacks rose close to 400% year-over-year in 2025, and they’re expected to rise again in 2026. These attacks are becoming increasingly sophisticated in their file return systems, too. To encourage payments, files are returned quickly and easily once a ransom payment is sent, providing positive reinforcement to people and businesses that pay.
Credit: Lino Mirgeler/Picture Alliance via Getty Images
But this is only making the situation worse, as it emboldens attackers. To try to put a stop to it, the UK government is working on legislation to prohibit public bodies such as the NHS, local councils, and schools from paying when their data is held hostage.
Security researchers warn, though, that re-extortion is a common tactic. Even if data is returned, it can easily be taken hostage again, and further payments demanded.
Others highlight that paying up is often the only clear option. For critical infrastructure such as utility companies, failing to pay could result in a halt in service. If blanket bans are put in place, they argue, innocent customers unaware of the hack may be negatively impacted. They highlight how bans in North Carolina and Florida in 2021 and 2022 didn’t do much to deter ransomware attacks.
Ultimately, security researchers argue, governments need to make ransomware less profitable to deter its prevalence. They can do that by improving security, since ransomware attacks still rely on typical malware and social engineering as initial attack vectors.
Another option some have suggested is a government-funded data backup infrastructure, so companies and organizations could more easily and affordably recover any lost data.