Ransomware surge pushes firms toward paying hackers

New Sophos data reveals that nearly half of ransomware victims pay up, as the UK government moves to ban ransom payments for public sector entities.

By Central
Sophos 2025 ransomware report shows 48% of victims pay, while UK advances ban on ransom payments to public sector and critical infrastructure.
Highlights
  • According to Sophos, 48% of companies targeted by ransomware end up paying a ransom to recover their data.
  • The UK government is advancing legislation to ban ransom payments by public sector and critical national infrastructure organizations.
  • Attackers are increasingly using AI to launch ransomware attacks, while defenders adopt AI-powered tools to counter them.

Nearly half of companies that fall victim to a ransomware attack end up paying a ransom to recover their data or systems, according to 2025 research from cybersecurity firm Sophos, while the median amount demanded by hackers continues to climb. This stark statistic arrives as governments worldwide grapple with how to respond. In the United Kingdom, authorities are advancing plans to prohibit public sector bodies and critical national infrastructure organizations—including the National Health Service, local councils, and schools—from making any ransom payments. The move underscores a growing tension: paying ransoms may offer a short-term fix for individual victims, but it also fuels a rapidly professionalizing cybercrime ecosystem that is now leveraging artificial intelligence to launch attacks at unprecedented scale and speed.

Nearly Half of Ransomware Victims Pay: The 2025 Sophos Data

The Sophos research, released in 2025, captures a sobering reality for organizations of all sizes. Approximately 48 percent of companies that are targeted by a ransomware attack end up paying a ransom to regain access to encrypted data or locked systems. The median payment demanded has also risen, reflecting the increasing sophistication and financial ambition of threat actors. While the exact median figure is not specified in the report, the trend signals that ransomware is no longer a nuisance crime carried out by lone operators; it is a high-stakes extortion business with growing leverage over victims.

The data underscores a critical inflection point. As more companies pay, attackers gain both the revenue and the confidence to demand even larger sums. This cycle creates a self-reinforcing dynamic that makes the decision to pay or not pay one of the most divisive issues in cybersecurity today.

UK Government Moves to Ban Ransom Payments for Public Sector and Critical Infrastructure

In response to the escalating threat, the UK government is pushing forward with legislation that would ban ransom payments by public sector entities and organizations deemed critical national infrastructure. This includes the National Health Service, local councils, and schools—institutions that are frequent targets because they hold sensitive data and often operate with limited cybersecurity budgets. The proposed ban is designed to starve ransomware groups of the financial incentives that drive their operations.

However, the policy is not without controversy. Critics argue that a blanket ban could leave organizations with no recovery path if their data is not backed up or if decryption keys are the only way to restore operations. Andy Maus, head of cyber recovery services at DriveSavers, which specializes in hard drive data recovery, cautions that situations are almost always more nuanced than a ban accounts for. “Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” Maus says. His perspective highlights the real-world dilemma: when lives or essential services are on the line, the theoretical purity of a no-payment policy may collide with practical necessity.

The AI-Driven Transformation of Ransomware Attacks

Behind the surge in both the frequency and severity of ransomware attacks lies a powerful enabler: artificial intelligence. Dave Spillane, systems engineering director at Fortinet, reports that confirmed ransomware victims rose 389 percent year-on-year in 2025, jumping from approximately 1,600 in 2024 to 7,831 globally. This exponential growth, Spillane notes, is powered by the rise of malicious AI hacking tools such as WormGPT, FraudGPT, and BruteForceAI. These tools automate and accelerate every stage of an attack, from reconnaissance to exploitation to extortion.

“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” Spillane explains. The efficiency gains are staggering. AI reduces the labor required to craft convincing phishing emails, identify vulnerabilities, and deploy ransomware across networks. What once demanded a skilled programmer now requires only a subscription to a malicious AI service and a basic understanding of how to aim it.

Shashi Kiran, chief marketing officer of tech group Nile, puts the transformation in stark terms: “The cost per attack has dramatically decreased, commoditizing sophisticated attacks, whereas the cost to defend is increasing. What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.” This commoditization is the single most disruptive force in the current ransomware landscape. It lowers the barrier to entry, expands the pool of attackers, and makes it nearly impossible for any organization to assume it is too small or too obscure to be targeted.

How AI Lowers the Cost of Ransomware Attacks

To understand the scale of the shift, consider the economics. Traditional ransomware operations required significant upfront investment: purchasing exploit kits, renting botnets, and paying developers to write customized code. AI tools like WormGPT and FraudGPT are often available as cheap, subscription-based services on dark web forums. They can generate persuasive spear-phishing emails in multiple languages, scan for software vulnerabilities, and even automate the negotiation process with victims. This automation reduces the time and expertise needed to carry out an attack from weeks or days to hours. The result is a flood of incidents that security teams can barely keep up with.

The Debate Over Paying: Does Ransom Payment Fuel the Ecosystem?

The question of whether to pay a ransom is not merely a financial calculation; it is a strategic decision with long-term consequences for the entire cybersecurity ecosystem. Jim Walter, a senior threat researcher at SentinelOne, takes an uncompromising stance. “Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he argues. Walter points out that threat actors cannot be trusted to delete data upon payment. Re-extortion and the ongoing monetization of stolen data are commonplace. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion,” he adds.

Walter’s position is grounded in evidence. Multiple case studies show that organizations that pay a ransom are often targeted again, sometimes by the same group, because they are flagged as willing payers. Moreover, the stolen data is rarely deleted; it may be sold on underground markets or used for additional attacks against the victim’s customers or partners.

What Are the Risks of Paying a Ransomware Demand?

Paying a ransomware demand carries several well-documented risks. First, there is no guarantee that the decryption key will work or that the attacker will provide it at all. Second, paying marks the organization as a compliant target, increasing the likelihood of repeat attacks. Third, it may violate sanctions or laws in jurisdictions that prohibit payments to designated terrorist groups or state-sponsored actors. Fourth, even if data is recovered, it may have been exfiltrated and could be leaked or used for future extortion. Finally, paying fuels the broader criminal economy, enabling attackers to invest in better tools and infrastructure. These risks make the decision to pay a high-stakes gamble rather than a reliable solution.

Yet not everyone is willing to adopt a blanket refusal to pay. Andy Maus of DriveSavers argues that the reality on the ground is often more complex than policy can account for. “Situations are almost always more nuanced than a ban accounts for,” he says. For a hospital that cannot access patient records, or a local council that cannot process welfare payments, the immediate human cost of not paying may outweigh the long-term risks of funding cybercrime. Maus’s perspective reflects the difficult trade-offs that organizations face when the theoretical ideal of a no-payment policy collides with the urgent need to restore operations.

How Ransomware Groups Have Evolved into Corporate-Style Operations

Haydn Brooks, chief executive of supply chain security group Risk Ledger, describes the current ransomware landscape as “a highly sophisticated, corporate-style ecosystem.” He notes that ransomware groups now operate like smart B2B operations, focusing on customer satisfaction and data return to maintain their reputation. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high,” Brooks says.

This evolution is critical to understanding why the debate over payment is so heated. Modern ransomware groups are not just vandals; they are professional organizations with customer support, negotiation teams, and even performance metrics. They have learned that a victim who gets their data back without incident is more likely to pay again, or to recommend payment to others. This corporate approach has made ransomware more effective and more profitable, while also making it harder for organizations to resist the pressure to pay.

The Rise of Ransomware-as-a-Service (RaaS)

Underpinning this corporate evolution is the Ransomware-as-a-Service (RaaS) model. Affiliates can rent ransomware infrastructure from developers, splitting the proceeds of successful attacks. This model has lowered the barrier to entry even further, allowing individuals with minimal technical skills to launch sophisticated attacks. The rise of AI tools has supercharged RaaS, enabling affiliates to automate targeting, delivery, and negotiation. The result is a self-sustaining criminal economy that adapts quickly to defensive measures.

The Growing Cost of Defense and the Commoditization of Attacks

As Kiran of Nile observed, the cost of defending against ransomware is rising while the cost of attacking is falling. This asymmetry is a fundamental challenge for cybersecurity teams. Organizations must invest in endpoint detection and response systems, employee training, backup infrastructure, incident response retainer services, and cyber insurance. The total cost of a robust defense can run into millions of dollars for mid-sized enterprises. Meanwhile, a single AI-powered phishing campaign can be launched for a few hundred dollars, with the potential to cause millions in damages.

The economic imbalance is unsustainable. Security teams are already stretched thin, and the influx of AI-driven attacks is only increasing the pressure. Many organizations are turning to cyber insurance as a safety net, but insurers are responding by raising premiums, tightening coverage terms, and demanding proof of strong security controls. Some policies now explicitly exclude coverage for ransom payments, leaving companies to bear the full cost of a breach.

What Is Driving the 389 Percent Increase in Confirmed Ransomware Victims?

The 389 percent year-on-year increase in confirmed ransomware victims, from roughly 1,600 in 2024 to 7,831 in 2025, is driven by three factors. First, the proliferation of AI tools has made attacks easier and cheaper to execute, leading to a dramatic rise in volume. Second, attackers are targeting smaller organizations that may lack the resources to defend themselves effectively. Third, the RaaS model has expanded the pool of attackers, allowing more individuals to participate in ransomware campaigns. These forces together have created a perfect storm of increased victimization that shows no signs of abating.

The Future of Ransomware: AI, Regulation, and the Urgent Need for New Strategies

As ransomware continues to professionalize and scale, the cybersecurity industry faces a critical juncture. The UK’s proposed ban on public sector payments is a significant regulatory experiment, but it remains to be seen whether it will reduce attacks or simply shift the burden onto private sector victims. Other jurisdictions are likely to watch closely, and similar measures could follow in the European Union, Australia, and parts of the United States.

On the technical front, defenders are also turning to AI to counter AI-powered attacks. Machine learning models that can detect anomalous behavior in real time, automated threat intelligence platforms, and AI-driven incident response tools are becoming essential components of modern security architectures. However, the arms race between attackers and defenders is likely to intensify, with each side leveraging ever more sophisticated AI capabilities.

For organizations, the most practical path forward involves a combination of preparation, prevention, and resilience. Robust backup strategies that are regularly tested, employee training that recognizes AI-generated phishing attempts, and strict access controls can reduce the likelihood of a successful attack. But no organization can be completely immune. The ability to recover quickly without paying a ransom—through clean backups, offline data copies, and well-practiced incident response plans—will become a competitive advantage in an era where ransomware is a near-certainty for most businesses.

The final lesson from the 2025 data is stark: ransomware is not going away, and it is getting smarter, faster, and more dangerous. The choice to pay or not to pay will remain agonizing, but the long-term health of the digital economy depends on breaking the cycle of extortion. Whether through regulation, technology, or collective action, the industry must find ways to reduce the profitability of ransomware, or the surge of attacks will only accelerate.

Share This Article