Governments Weigh Ransomware Payment Bans
Governments have reportedly begun banning ransomware payments to hackers as demand amounts continue to rise.
That’s according to a report Monday (July 20) from the Financial Times (FT), which cites the example of the U.K.’s planned ban on ransomware payouts from public sector organizations and “critical national infrastructure groups.”
According to the report, this proposal is happening at a moment when hackers have become more advanced and more careful in targeting companies, especially small and medium-sized businesses (SMBs).
“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” Haydn Brooks, chief executive of supply chain security group Risk Ledger, told the FT. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.”
And Dave Spillane, systems engineering director at Fortinet, said this trend has been fueled by the arrival of AI hacking tools, with the number of confirmed ransomware victims jumping from 1,600 in 2024 to 7,831 in 2025, a 389% increase.
“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” said Spillane.
However, the FT added, the question of whether to pay hackers remains a matter of heated debate in cybersecurity circles.
Jim Walter, a senior threat researcher at SentinelOne, said his company is staunchly opposed to responding to ransoms.
“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he said, adding that there is no guarantee hackers will delete data upon payment. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.”
Others are less certain, like Andy Maus, head of cyber recovery services at DriveSavers, a company that recovers hard drive data.
“Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” Maus said. “Situations are almost always more nuanced than a ban accounts for.”
In other cybersecurity news, recent PYMNTS Intelligence/Trulioo research examined the problem of verification friction for businesses.
“The findings suggest that identity verification now sits at the intersection of compliance, customer acquisition and revenue protection,” PYMNTS wrote last week.
“Financial services firms are trying to serve more customers through mobile apps, digital onboarding and embedded financial products. At the same time, they face synthetic identity fraud, account takeover, stolen identity and adversarial bots. The more digital the business becomes, the more identity gaps can spread across the customer journey.”