All posts

UK moves to ban ransomware payments from public sector

Huma ShaziaJuly 21, 2026 at 9:17 AM5 min read
UK moves to ban ransomware payments from public sector

Key Takeaways

UK Ransomware Payment Ban: What It Means for Public and Private Sector Cybersecurity

UK moves to ban ransomware payments from public sector
Source: PYMNTS |
  • UK proposes banning ransomware payments from public sector and critical infrastructure organizations
  • Confirmed ransomware victims rose from 1,600 in 2024 to 7,831 in 2025, a 389% increase
  • Security experts remain divided on whether payment bans help or hurt victims

The UK government is preparing to ban ransomware payments from public sector organizations and critical national infrastructure groups. The proposal arrives as confirmed ransomware victims surged 389% year-over-year, from 1,600 in 2024 to 7,831 in 2025, according to data cited by the Financial Times.

The question of whether governments should prohibit ransom payments has divided cybersecurity professionals for years. This UK proposal marks one of the most significant policy moves to date, targeting the revenue stream that keeps ransomware gangs profitable.

Advertisements

Why ransomware attacks have exploded

Dave Spillane, systems engineering director at Fortinet, attributes the surge to AI-powered hacking tools. These tools have compressed the time needed to execute attacks, allowing hackers to target four organizations simultaneously in the time it previously took to hit one.

Haydn Brooks, CEO of supply chain security group Risk Ledger, described the current threat landscape to the Financial Times: "In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem. While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high."

The numbers back up this assessment. Average ransomware payments have climbed from around $400,000 in 2020 to over $5 million in 2023. Total payments to ransomware attackers exceeded $1.1 billion globally that year, according to Chainalysis data. The average downtime after an attack runs 21 days, during which businesses hemorrhage revenue and trust.

The case against paying ransoms

Jim Walter, senior threat researcher at SentinelOne, represents the hardline view. "Paying extortive threat actors only strengthens the ecosystem and the entities that enable it," he told the Financial Times. "Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion."

Walter raises a practical point: there is no guarantee hackers will delete stolen data after receiving payment. Many victims have paid only to find their data leaked anyway, or to be targeted again months later by the same group.

FBI Director Christopher Wray has compared ransom payments to "pouring gasoline on a fire," arguing that each payment directly funds the next attack. This logic underpins the UK proposal: if victims cannot pay, the business model collapses.

Why some experts hesitate on blanket bans

Not everyone is convinced. Andy Maus, head of cyber recovery services at DriveSavers, questions what happens when recovery is impossible. "Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible," Maus said. "Situations are almost always more nuanced than a ban accounts for."

Ciaran Martin, former head of the UK's National Cyber Security Centre, has previously noted that a blanket ban "sounds good in theory, but it could be catastrophic for a hospital with lives on the line." A hospital facing permanent loss of patient records or a utility unable to restore service faces a different calculus than a company losing sales data.

worldpay
worldpay

The UK proposal attempts to thread this needle by targeting public sector and critical infrastructure, leaving private businesses with a choice. Whether this distinction holds under political pressure remains to be seen.

Advertisements

What this means for SMBs

Small and medium-sized businesses face the sharpest edge of this trend. Hackers have grown more careful in targeting companies with limited security budgets but enough revenue to pay. A payment ban that applies only to government and critical infrastructure could push attackers further toward private-sector SMBs.

The average total cost of a ransomware breach, including recovery, runs $4.54 million according to IBM's Cost of Data Breach Report. For an SMB, that figure can be existential. Yet paying offers no guarantee of data return, and increasingly carries legal risk if the ransomware group is on a sanctions list.

The verification problem compounds the risk

Recent PYMNTS Intelligence and Trulioo research highlights a related challenge: identity verification friction. As financial services firms push more customers through mobile apps and digital onboarding, they face synthetic identity fraud, account takeover, and adversarial bots. Each digital touchpoint creates new vulnerabilities that ransomware groups can exploit.

"The more digital the business becomes, the more identity gaps can spread across the customer journey," PYMNTS noted. For finance teams, ransomware defense cannot be separated from broader identity and access management. A compromised credential often provides the initial entry point.

ℹ️

Logicity's Take

The UK's proposed ban is a calculated bet that cutting revenue will starve ransomware groups faster than it will bankrupt victims. For finance teams, the practical implication is clear: you cannot rely on payment as a backstop. Incident response planning, offline backups tested quarterly, and cyber insurance policies that do not exclude ransomware become non-negotiable. The 389% surge in victims also suggests that current defense spending is falling short. CFOs should expect security budget requests to rise, with vendors like CrowdStrike, SentinelOne, and Fortinet competing for that spend.

Frequently Asked Questions

Does paying ransomware guarantee data recovery?

No. Security researchers report that many victims who pay never receive working decryption keys, or find their data leaked anyway. Payment also marks you as a willing payer, increasing the chance of repeat attacks.

Is it illegal to pay ransomware in the US?

Not directly, but payments to sanctioned entities violate OFAC regulations. Several ransomware groups are on sanctions lists, making payment legally risky even where not explicitly banned.

Why are SMBs targeted more frequently?

SMBs often have weaker security controls and smaller IT teams, but still hold valuable data and enough revenue to pay ransoms. Attackers view them as high-return, low-effort targets.

How long does ransomware recovery typically take?

The average downtime after a ransomware attack is 21 days. Full recovery, including forensic investigation and system hardening, often takes longer.

Also Read
Singapore tightens PSP audits: what the new MAS rules require

Another example of regulators tightening financial sector security requirements

ℹ️

Need Help Implementing This?

Contact Logicity's editorial team for coverage of your company's cybersecurity initiatives or to discuss sponsored content opportunities in our fintech and finance coverage.

Source: PYMNTS | / PYMNTS

H

Huma Shazia

Senior AI & Tech Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.