Tech

UK advances ransomware payment ban as global attacks surge 389 per cent

Experts warn blanket prohibitions may shift pressure to the private sector and inflate insurance premiums, while calling for stronger technical hygiene and backup infrastructure.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · original
Pay up or not? Ransomware surge has victims facing tough choices
Regulatory shift comes amid commoditisation of hacking tools via malicious AI

The UK government is advancing legislative plans to prohibit public sector bodies and critical national infrastructure groups from paying ransomware demands, a move designed to cut off funding to criminal ecosystems. The proposed ban would apply to entities such as the National Health Service, local councils, and schools, responding to a sharp escalation in cyber threats. This regulatory shift occurs against a backdrop of a reported 389 per cent year-on-year increase in global ransomware victims in 2025, with figures rising from approximately 1,600 in 2024 to 7,831.

Research from cyber security group Sophos indicates that nearly half of companies targeted by ransomware in 2025 paid the ransom, with the median demand rising. Industry leaders describe the current landscape as a highly sophisticated, corporate-style ecosystem. Haydn Brooks, chief executive of supply chain security group Risk Ledger, noted that while ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.

The surge in attacks has been powered by the rise of malicious AI hacking tools, specifically WormGPT, FraudGPT, and BruteForceAI. Dave Spillane, systems engineering director at Fortinet, stated that these tools have commoditised sophisticated attacks, allowing hackers to target four organisations simultaneously in the time previously required for one attack. Shashi Kiran, chief marketing officer at tech group Nile, added that what previously required nation-state resources can now be accomplished by individuals with limited skills leveraging AI.

Despite the push for bans, security professionals argue that blanket prohibitions may not deter criminals and could cause unintended harm. Andy Maus, head of cyber recovery services at DriveSavers, warned that bans may cause more harm than good in scenarios where data recovery is not feasible, particularly for critical infrastructure like water or power utilities. He noted that statewide bans in North Carolina and Florida, introduced in 2021 and 2022 respectively, have not materially deterred criminal activity.

Brooks at Risk Ledger cautioned that banning public sector payments could cause cyber criminals to aggressively pivot to the unregulated private sector, driving up cyber insurance premiums as costs dwarf original ransom demands. Instead of prohibitions, experts from Tenable, SentinelOne, and Delinea emphasise that long-term solutions lie in exposure management, technical hygiene, multi-factor authentication, and limiting access permissions. Maus suggested that government investment in subsidized backup infrastructure or tax incentives for cybersecurity spending would be more effective than payment bans.

Continue reading

More from Tech

Read next: France Enacts Strict Ban on Unsolicited Telemarketing Calls
Read next: OpenAI expands Daybreak cybersecurity programme with new model tiers
Read next: AI models map 766 genes in schizophrenia genetic architecture