LONDON—Governments in several countries are weighing bans on ransomware payments as cybercriminals become more sophisticated and increasingly target organizations with AI-assisted attacks, according to new report.
The news comes at the same time numerous credit unions have found themselves the victims of ransomware attacks that have shut down systems and led to significant issues for members.
The Financial Times reported that the U.K. is moving forward with plans to prohibit ransomware payments by public sector organizations and operators of critical national infrastructure, part of a broader effort to reduce the financial incentives that fuel cybercrime.

The proposal comes as ransomware groups adopt increasingly professionalized business models while expanding their attacks, particularly against small and medium-sized businesses, the report said.
Risks Reach ‘Unprecedented Levels’
“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” Haydn Brooks, CEO of supply chain security firm Risk Ledger, told the Financial Times. While many ransomware groups operate like businesses that often return data after payment, Brooks said the legal and sanctions risks associated with paying ransoms have reached unprecedented levels.
The growing threat has been accelerated by artificial intelligence, according to Dave Spillane, systems engineering director at cybersecurity company Fortinet.
Spillane told the newspaper that confirmed ransomware victims increased from approximately 1,600 in 2024 to 7,831 in 2025, a 389% jump, driven in part by AI-powered hacking tools that allow cybercriminals to scale their operations.
“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” Spillane said.
Divided Opinions
Despite the rising threat, the Financial Times reported that cybersecurity experts remain divided over whether organizations should ever pay ransom demands.
Jim Walter, senior threat researcher at SentinelOne, argued that paying attackers only strengthens the criminal ecosystem.
“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” Walter told the newspaper, adding there is no guarantee cybercriminals will delete stolen data after receiving payment. “Paying absolutely does not guarantee recovery; it actually encourages further crime and extortion.”
Unintended Consequences
Others caution that an outright ban could create unintended consequences.
Andy Maus, head of cyber recovery services at DriveSavers, a data recovery company, said organizations can face situations where restoring data without paying a ransom is impossible.
“Our concern with a ban is what happens when a payment ban is in place, but data recovery is not feasible,” Maus told the Financial Times. “Situations are almost always more nuanced than a ban accounts for.”




