Ransomware victims are still paying cybercriminals in striking numbers, even as official guidance warns that a payment may not restore data, prevent disclosure, or end the attack. A new survey of security professionals found that 58% of UK organizations affected by ransomware paid a ransom, yet 22% of those payers received a second extortion demand. The finding exposes the grim reality behind ransomware incident response: under intense operational pressure, many businesses treat payment as a recovery mechanism, while attackers increasingly treat it as the beginning of a longer and more profitable negotiation.
The results arrive as UK policymakers pursue stronger measures intended to disrupt the ransomware economy, including a proposed ban on payments by public-sector organizations and operators of critical national infrastructure. But the statistics show why policy alone cannot solve the problem. When critical systems are unavailable, customers cannot be served, staff cannot work, clinical services are affected, and sensitive data appears destined for publication, the theoretical principle of “never pay” collides with an immediate business-continuity crisis.
For Windows administrators, IT leaders, and security teams, the central lesson is increasingly clear: ransomware resilience has to be established before the intrusion, not improvised after a ransom note appears. Backups, identity security, endpoint visibility, tested recovery plans, network segmentation, and practiced executive decision-making all matter more when the adversary has already stolen data and is threatening to leak it.

Cybersecurity team monitors a ransomware attack dashboard showing encrypted files, ransom demands, and response plans.The Ransomware Payment Paradox​

The traditional ransomware playbook was brutally simple. Attackers encrypted files, displayed a ransom demand, and offered a decryption key in exchange for cryptocurrency. Victims faced a binary choice: pay or attempt to restore from backups.
That model has changed. Modern ransomware operations routinely combine encryption with data theft, credential harvesting, persistence mechanisms, and the threat of public disclosure. This approach is often described as double extortion, although some criminal groups now apply multiple layers of pressure, including direct contact with executives, customers, suppliers, regulators, and journalists.
In this environment, a ransom payment is not a clean transaction. The victim is not buying a guaranteed product from a trustworthy vendor. It is attempting to negotiate with an adversary that has already demonstrated a willingness to break into systems, steal information, disrupt operations, and use coercion for profit.
The reported UK payment rate of 58% should therefore not be read as proof that organizations are comfortable funding cybercrime. It is better understood as evidence of how frequently businesses find themselves without an acceptable recovery path once an attack reaches its final stage.
Several conditions can make payment appear attractive:
  • Core systems are unavailable, preventing normal business operations.
  • Backups are incomplete, inaccessible, or untested.
  • Attackers claim to have stolen customer, employee, financial, or intellectual-property data.
  • Senior leaders fear regulatory exposure, litigation, or reputational damage.
  • Downtime costs appear greater than the ransom demand.
  • Cyber insurance, legal advisers, or incident-response partners are involved in evaluating a payment.
  • The affected organization lacks a rehearsed ransomware response plan.
None of these conditions makes payment safe. They simply explain why an organization that publicly supports a non-payment policy may reach a different conclusion during a real crisis.
That disconnect is one of ransomware’s most damaging characteristics. Businesses may assume that a formal policy provides protection, but a policy without resilient technical controls, recovery capacity, and clear authority to make decisions is often little more than an aspiration.

Paying Does Not End the Incident​

The most consequential detail in the survey is not merely that a majority of affected UK organizations paid. It is that more than one in five organizations that paid were hit with another extortion demand.
This reflects a change in the criminal business model. Attackers no longer need to rely solely on a decryptor as their source of leverage. They can retain stolen files, credentials, screenshots, cloud tokens, customer data, source code, and other artifacts that can be reused long after the victim has restored systems.
A victim might receive a decryption tool after payment, only to face a second demand based on stolen data. Alternatively, the attackers may claim that an affiliate retained a copy of the data, that a separate buyer acquired it, or that publication will proceed unless additional money is sent.
There is no reliable way for a victim to verify that stolen data has been deleted. Criminal groups may promise deletion, but that promise cannot be audited. Data may have been copied multiple times, shared internally, sold to other threat actors, or retained for future fraud and phishing campaigns.
This is why ransomware should not be framed exclusively as an encryption problem. Even a successful restoration of Windows servers, virtual machines, databases, and endpoints may leave the organization with a serious data-security incident.

The Decryptor Is Not a Recovery Strategy​

Even when attackers provide a valid decryptor, it may not return a complex Windows environment to normal operation quickly. Decryption across a large estate can take days or weeks, particularly when attackers have encrypted file servers, virtualization hosts, domain services, databases, line-of-business systems, and remote endpoints.
The decryptor itself may be slow, unstable, or incomplete. It may fail against certain file types or leave systems in an inconsistent state. Security teams must also assume that the attacker may still have access through stolen credentials, remote management tools, compromised VPN accounts, cloud identities, or persistence mechanisms planted before encryption.
In many cases, restoring from clean, immutable backups is faster and safer than decrypting systems one by one. However, that advantage exists only when those backups are isolated from the production environment, regularly tested, and accompanied by clear recovery priorities.
A business that can restore its identity platform, communications tools, critical application servers, and essential data in a controlled sequence has a meaningful alternative to payment. A business that discovers its backups were encrypted alongside its production systems does not.

Why Official Advice and Operational Reality Diverge​

UK cyber authorities do not encourage, endorse, or condone ransom payments. The reasoning is straightforward: payments can finance criminal operations, make victims appear profitable, and provide no guarantee that systems or data will be recovered.
There are also legal and regulatory concerns. Payments involving sanctioned entities or jurisdictions can create serious compliance risks. A payment does not remove an organization’s responsibility to assess a personal-data breach, notify authorities where required, investigate the compromise, or protect affected individuals.
Yet official advice generally recognizes that the decision remains with the victim organization. That nuance matters. A ransomware attack can affect patient care, emergency services, public infrastructure, payroll, manufacturing, logistics, legal obligations, and the viability of a business itself.
The difficult question is not whether paying attackers is desirable. It is whether an organization has allowed itself to reach a point where payment appears to be the least harmful option.
That is why a ransomware strategy must include more than a declaration that the business will not pay. It needs to answer practical questions such as:
  1. Who can authorize a payment decision?
  2. Who communicates with law enforcement, insurers, legal counsel, and incident responders?
  3. How will the organization determine whether data was stolen?
  4. Which systems must be restored first to sustain critical operations?
  5. How long can manual workarounds remain viable?
  6. What happens if Microsoft Active Directory, Entra ID integrations, backup infrastructure, and endpoint management tools are all affected?
  7. How will the organization communicate internally if email and collaboration platforms are unavailable?
  8. How will it verify that the attacker has been removed before recovery begins?
Without tested answers, executive teams are forced to make high-stakes decisions with incomplete information and shrinking deadlines.

The Policy Case for Restricting Ransom Payments​

The proposed UK approach aims to reduce the financial incentives that drive ransomware. Measures under development include a ban on ransom payments by public bodies and critical national infrastructure operators, alongside enhanced reporting expectations and a notification process for organizations outside the ban that intend to make a payment.
The logic behind a targeted payment ban is compelling. Public services, schools, local authorities, healthcare providers, and critical infrastructure operators should not become dependable revenue sources for criminal groups. Restricting payment can also signal that attacks against essential services will not produce the expected financial reward.
Mandatory reporting could be equally important. Ransomware remains underreported, especially when victims fear reputational damage, regulatory consequences, or public scrutiny. Better reporting can give authorities a clearer picture of active groups, common initial access techniques, payment routes, affected sectors, and emerging indicators of compromise.
That intelligence can improve disruption efforts, strengthen sector-specific guidance, and help authorities warn other organizations before campaigns spread.

The Risk of Treating a Ban as a Security Control​

A payment ban is not the same as ransomware prevention. It may reduce incentives over time, but it cannot patch vulnerable systems, rebuild a compromised identity environment, or restore encrypted files.
There is also a danger that organizations affected by a ban may become more attractive targets for disruptive or politically motivated attacks. Criminal groups may conclude that they cannot profit through payment, but still seek to cause damage, steal data, or exploit the incident for publicity.
Enforcement creates another challenge. Punishing a victim organization for making a payment after a catastrophic cyberattack could appear to compound the harm. A company facing weeks of downtime, supply-chain disruption, public data exposure, and financial loss may argue that a payment was made to protect employees, customers, or essential services.
The stronger policy outcome is therefore not simply “ban payments.” It is ban payments while raising baseline cyber resilience, improving incident reporting, supporting victims, and ensuring critical organizations have the resources to recover without negotiating with criminals.

Data Theft Has Become the Primary Pressure Point​

The survey’s broader findings point to the accelerating shift from ransomware as a file-encryption event to ransomware as a data and identity compromise. A significant proportion of UK respondents reported that data was stolen during the attack.
That distinction changes how Windows environments must be defended.
Encryption is disruptive, but it is visible. Stolen credentials and copied data can remain hidden for weeks or months. An attacker who has captured privileged accounts, cloud tokens, VPN credentials, browser session cookies, or sensitive documents may be able to return after the apparent incident has ended.
For many organizations, the highest-value assets are not Windows workstations or servers in isolation. They are the identities, permissions, data stores, and trusted business communications that connect the environment.

The Windows Identity Problem​

In a typical enterprise, Active Directory remains central to identity, authentication, authorization, Group Policy, workstation management, and access to file shares and applications. A ransomware intrusion that reaches domain-controller privileges is not merely an endpoint incident. It can become a full identity compromise.
Attackers may:
  • Dump password hashes or target credential stores.
  • Create or modify privileged accounts.
  • Abuse service accounts with excessive permissions.
  • Alter Group Policy Objects.
  • Disable security tools through administrative access.
  • Deploy ransomware through centralized management systems.
  • Access file shares and backups using inherited privileges.
  • Move laterally through Remote Desktop Protocol, SMB, PowerShell remoting, or remote management tooling.
  • Establish persistence using scheduled tasks, services, startup items, or compromised federation infrastructure.
The recovery task then becomes far more difficult than restoring a handful of encrypted servers. Organizations may need to rebuild or remediate directory services, reset privileged credentials, revoke tokens, rotate secrets, validate trust relationships, and confirm that endpoint management tools are safe to use again.
A ransomware recovery plan that assumes the domain remains trustworthy after a domain-wide compromise is dangerously incomplete.

AI Is Improving the Attacks That Come Before Ransomware​

The new survey also found that a majority of ransomware victims believed artificial intelligence made the attack more effective. This does not mean that AI has magically transformed ransomware encryption. The more significant impact is earlier in the attack chain.
Generative AI can help threat actors create more fluent phishing emails, more convincing impersonation attempts, better localized messages, and more plausible pretexts for credential theft. It can reduce the obvious spelling errors and generic language that users once relied on as warning signs.
The result is a sharper form of social engineering aimed at the human and identity layers of security.
Reported findings indicate that users often interacted with malicious content because it appeared legitimate, while other attacks succeeded because employees did not suspect anything was wrong. That should concern every organization that still treats annual awareness training as its primary defense against phishing.

Security Awareness Must Become Behavior-Based Defense​

Employees cannot reasonably be expected to detect every polished impersonation attempt. Security programs must reduce the consequences of a single click, credential submission, or mistaken approval.
For Windows and Microsoft 365 environments, that means prioritizing controls such as:
  • Phishing-resistant multifactor authentication for privileged users and high-risk roles.
  • Conditional access policies that consider device health, location, sign-in risk, and impossible travel events.
  • Strong protection for help desks and identity-verification processes.
  • Restricted legacy authentication.
  • Least-privilege access and just-in-time administration.
  • Separate administrator accounts for privileged activity.
  • Tight controls on PowerShell, script execution, macros, and remote administration.
  • Email authentication using SPF, DKIM, and DMARC.
  • Attachment sandboxing and URL inspection.
  • Endpoint detection and response capable of identifying suspicious lateral movement.
  • Monitoring for unusual OAuth consent grants, token abuse, mailbox rules, and anomalous sign-ins.
The goal is not to make users perfect. It is to ensure that one successful deception attempt cannot immediately become domain compromise, data exfiltration, and enterprise-wide encryption.

Building a Recovery Capability That Makes Payment Less Likely​

The most effective anti-ransomware measure is the ability to continue operating and recover safely without trusting the attacker. That requires investment in both prevention and restoration.

Protect and Test Backups​

A backup is only valuable if it can survive the attack and be restored within the required recovery window. Organizations should maintain multiple copies of critical data, including at least one immutable or offline copy that cannot be altered using normal administrative credentials.
Backup administration must be isolated from everyday domain administration. If a compromised domain administrator can delete backup jobs, alter retention settings, or access backup repositories, the backup system is part of the attack surface.
Recovery testing should include more than restoring a file. Teams need to test the restoration of:
  • Domain controllers and identity services.
  • Core Windows Server workloads.
  • Virtualized infrastructure.
  • Business-critical databases.
  • Microsoft 365 data and configuration where applicable.
  • Endpoint management services.
  • Security tooling and logging systems.
  • Network services such as DNS, DHCP, certificate services, and remote access.

Segment the Environment​

Flat networks allow ransomware to spread quickly. Network segmentation limits lateral movement and creates containment boundaries between user devices, servers, backups, administrative systems, operational technology, and sensitive data stores.
Segmentation is especially important for administrative pathways. A compromised standard workstation should not provide easy access to backup consoles, hypervisor management, domain controllers, or high-value production systems.

Treat Incident Response as an Operating Discipline​

A written ransomware plan is useful, but a rehearsed plan is far more valuable. Tabletop exercises should include executives, IT operations, security teams, legal counsel, communications leaders, HR, finance, and third-party providers.
Exercises should test uncomfortable scenarios: encrypted domain controllers, stolen customer records, unavailable email, attackers contacting the CEO, compromised backups, and a demand that expires overnight.
The objective is not to predict every attacker tactic. It is to ensure the organization can make disciplined decisions under pressure.

The Real Measure of Ransomware Readiness​

The headline figure of 58% is alarming, but it should not lead to simplistic conclusions about weak leadership or reckless security teams. Ransomware victims often make decisions in impossible circumstances created by years of technical debt, underinvestment, insufficient visibility, fragile backup systems, and dependencies that only become clear during failure.
Still, the figure is a warning. Too many organizations remain exposed to a form of cybercrime that offers attackers repeated leverage: encrypt the environment, steal the data, retain the credentials, threaten disclosure, and demand payment again.
The 22% second-extortion rate demonstrates why payment cannot be treated as resolution. It may buy time, provide a decryptor, or reduce immediate pressure, but it does not erase the compromise. It does not prove that data was deleted. It does not satisfy regulatory obligations. And it does not prevent future attacks if the original access path remains open.
The organizations best positioned to resist ransom demands will be those that view ransomware as an identity, data, resilience, and governance problem, not merely an endpoint malware problem. For Windows environments, that means defending privileged access, protecting backups from administrative compromise, limiting lateral movement, detecting suspicious behavior early, and practicing recovery until it becomes a repeatable operational capability.
Ransomware gangs thrive when victims believe there is no alternative. The most important security investment is therefore the one that proves there is.

References​

  1. Primary source: IT Pro
    Published: 2026-07-23T11:32:48+00:00
  2. Related coverage: gov.uk
  3. Related coverage: axios.com