Ransomware surge forces governments and businesses into an old dilemma with higher stakes

Ransomware is on a trajectory that is forcing a reckoning. Claimed attacks surged 50% in 2025, the most active year on record, with more than 8,000 organisations publicly named on leak sites. The median ransom demand jumped from roughly US$12,700 in 2024 to nearly US$60,000 in 2025. And yet the share of victims who pay has dropped to an all-time low of 28%, according to Chainalysis’s 2026 Crypto Crime Report.

The paradox sits at the centre of a debate playing out in boardrooms and legislative chambers alike: does banning ransom payments help, or does it leave unprepared victims with no escape route?

The argument for a ban rests on straightforward economics. Ransomware exists because it pays. Cut off the payments, and the model collapses. An alliance of 48 countries has pledged not to pay ransoms, though most lack binding legislation. The UK has confirmed a public-sector payment ban, and several US states, North Carolina, Florida, and Tennessee among them, have passed or considered similar restrictions for government agencies.

But the case against a blanket ban is stubbornly practical. The Ransomware Task Force at the Institute for Security and Technology argued that a ban at the current time would worsen harm to victims. Small businesses cannot withstand lengthy disruptions; hospitals, schools, and local governments are least prepared to restore operations from backups alone. The task force recommended a phased, multi-year approach: building ecosystem preparedness, deterrence, disruption capabilities, and victim support before making payments illegal.

Support independent reporting built on evidence, transparency, and scientific rigor.

Make a difference

“The more important question is how to make ransomware less profitable in the first place,” said Gavin Millard, vice-president of product at a cybersecurity firm, as quoted by the Financial Times.

The data suggests the pressure is already shifting behaviour. Total ransomware payments fell for a second consecutive year in 2025, coming in at roughly US$820 million, down about 8% from 2024. More victims are restoring from backups rather than paying. But attackers are compensating through volume and higher demands per victim. A single attack on Jaguar Land Rover in late 2025 caused an estimated US$2.5 billion in damage.

For policymakers, the question is whether to accelerate the decline in payment rates through legislation or let market forces and improved defences continue the trend, and whether governments can afford to wait.

Sources: Pay up or not? Ransomware surge has victims facing tough choices (Ars Technica/Financial Times, July 2026); Should Ransomware Payments Be Banned? What the Laws Say in 2026 (STACK Cybersecurity, May 2026)

Scroll to Top