To Pay or Not to Pay? Victims Confront Difficult Decisions Amid Ransomware Surge

According to a 2025 report from the cybersecurity firm Sophos, almost 50% of businesses targeted by ransomware attacks ultimately opt to pay the ransom to restore their data or systems. This alarming trend is coupled with a notable increase in the median ransom amounts demanded by cybercriminals.

In response to this escalating crisis, several jurisdictions worldwide are exploring legal measures to prohibit ransom payments. The United Kingdom is notably advancing plans to ban public sector entities and critical infrastructure organizations—including the National Health Service, local councils, and educational institutions—from making such payments. This potential legislation highlights the growing concern over the rising sophistication of ransomware attackers, particularly as they increasingly focus on small and medium-sized enterprises.

Experts warn that by 2026, the ransomware landscape has transformed into a highly organized ecosystem resembling corporate operational models. Haydn Brooks, CEO of Risk Ledger, points out that ransomware groups now function akin to business-to-business organizations, strategically optimizing the chances of data recovery. However, he stresses that the legal repercussions and sanctions related to paying ransoms are currently at unprecedented levels.

The sophistication of attacks has been further exacerbated by the introduction of malicious AI-driven hacking tools like WormGPT, FraudGPT, and BruteForceAI. Dave Spillane from Fortinet reports a staggering 389% year-on-year increase in confirmed ransomware victims in 2025, skyrocketing from approximately 1,600 in 2024 to 7,831 globally. He notes that the speed of attacks has also amplified; hackers can now target multiple organizations simultaneously, increasing the number of potential victims within the same time frame.

The economics of cybercrime have shifted dramatically. Shashi Kiran, Chief Marketing Officer of Nile, indicates that the cost associated with executing sophisticated ransomware attacks is decreasing, thereby commodifying such strikes. In contrast, the expenses tied to defensive measures are on the rise. Kiran points out that techniques once reserved for nation-states can now be exploited by individuals equipped with relatively minimal skills, thanks to the capabilities of modern AI.

In analyzing the attack methods employed by these cyber adversaries, various tactics from the MITRE ATT&CK framework seem particularly relevant. Initial access, persistence, and privilege escalation are among the techniques that these attackers likely leverage, allowing them to infiltrate systems and establish lasting control. As the cybersecurity landscape continues to evolve, business owners must remain vigilant and adapt their security strategies to counter these emerging threats.

Source