US National Wire
Tech

The Ransom Reckoning: Who Pays When the Payouts Are Banned?

Portrait of Alicia Ferro
Alicia Ferrofintech & paymentsJul 21AI
The Ransom Reckoning: Who Pays When the Payouts Are Banned?

AI-generated image · US National Wire

As governments move to outlaw ransomware payments, the financial burden is shifting from the hackers to the insurance markets and the private sector.

The debate over ransomware payments is shifting from a security dilemma to a systemic financial risk. While the instinct to pay is driven by the need for data recovery, a growing movement to ban these payouts is poised to rewrite the economics of cyber insurance and corporate liability.

According to reporting from Ars Technica, the scale of the threat has exploded due to AI-powered tools like BruteForceAI, FraudGPT, and WormGPT. Dave Spillane, systems engineering director at Fortinet, reports that confirmed ransomware victims surged 389% year-on-year in 2025, climbing from approximately 1,600 in 2024 to 7,831 globally. Shashi Kiran, chief marketing officer of Nile, notes that AI has commoditized these attacks, allowing individuals with limited skills to execute operations that previously required nation-state resources.

In response, some jurisdictions are implementing hard bans. The UK government is currently advancing plans to prohibit payouts from public sector bodies and critical national infrastructure, including local councils, schools, and the National Health Service. Similar statewide bans were introduced in Florida in 2022 and North Carolina in 2021, though Andy Maus, head of cyber recovery services at DriveSavers, observes that neither appears to have materially deterred criminal activity.

From a market perspective, these bans create a dangerous vacuum. Haydn Brooks, CEO of Risk Ledger, warns that without payouts from critical national infrastructure, cybercriminals will likely pivot aggressively toward the unregulated private sector. More critically for the fintech and insurance space, Brooks notes that if public bodies are barred from paying, the cyber insurance market will inevitably shift to exclude these payouts, which could drive premiums "sky-high" as the resulting costs far exceed the original ransom demands.

The divide over the efficacy of payments remains sharp. Jim Walter, a senior threat researcher at SentinelOne, argues that paying only strengthens the criminal ecosystem and offers no guarantee of recovery, as re-extortion and the sale of stolen data are common. Conversely, Maus of DriveSavers argues that blanket prohibitions ignore the nuance of critical infrastructure—such as power or water providers—where a failure to recover data could cause serious harm to customers.

As the risk model shifts, a secondary economy of breach coaches, incident response teams, and ransom negotiators has emerged to help firms navigate these choices. However, industry experts suggest the long-term solution is technical rather than legislative. Gavin Millard, VP of product at Tenable, argues the focus should be on "exposure management" to make ransomware less profitable, while Spencer Young, international senior vice-president at Delinea, emphasizes the need for strong access controls to shrink the "blast radius" of an attack.

Sources

More from Alicia Ferro