Nearly half of companies hit by ransomware end up paying the hackers, according to Sophos research. The median demand keeps climbing while legal bans on payouts are gaining traction. In the UK, public sector bodies and critical infrastructures face a potential ban.
The sophisticated nature of modern ransomware attacks is due in part to malicious AI tools like WormGPT and FraudGPT. These have led to a 389% year-on-year rise in confirmed victims globally. The cost per attack has decreased, making these crimes more accessible than ever.
Meanwhile, experts caution that paying ransoms only fuels the problem. Haydn Brooks of Risk Ledger argues that while data return is promised, it’s rarely delivered. Re-extortion and further monetization of stolen data are commonplace.
The decision to pay or not remains highly divisive in cybersecurity circles. While some advocate a hard line against responding to ransoms, others argue that bans might force companies into paying anyway if recovery isn’t feasible.







