Email Security Evolution

Ransomware: Should You Pay or Not in 2025?

Thousands of organizations fell prey to ransomware attacks in 2024. In some cases, ransom demands soared so high that one Fortune 50 company was forced to pay $75 million to get back to operations.

Perpetrators are not backing down in 2025. Because ransomware groups learn to adopt new tactics and attract more affiliates, more organizations may find themselves at the mercy of ruthless threat actors next year. Worse yet, ransom demands can become even more outrageous.

Despite a ransomware payment controversy, some companies still decide to yield to the attacker’s requests. Doing so may seem like the easiest way out, but it comes with its own set of complications, both ethical and legal.

Ethical and Practical Considerations in Ransom Payments

Before organizations decide to make a ransomware payment, they should ask themselves, “Are we perpetuating a cycle of crime and reinforcing the very behavior we are trying to root out?”

From an ethical standpoint, paying a ransom means conceding to criminals and indirectly funding illicit activity. This perspective lets you realize that ransomware and corporate responsibility are closely intertwined, as making the payment can affect your organization’s impact on society. The money you’re transferring to threat actors could then be used to target society in more detrimental ways, making your business partly responsible for the outcomes.

The ethical issue aside, paying a ransom always entails practical risks like:

  • You don’t get what you have bargained for. You never know whether agreeing to the attacker’s terms will salvage your data and operations. There have been many cases when decryption keys provided by ransomware groups turned out to be useless. There’s a chance your money goes down the drain without network restoration.
  • It increases the likelihood of becoming a future target. Cybercriminals keep an eye out on organizations that have previously paid ransoms. The idea is that if a company gives in to pressure at least once, it is more likely to pay if it is struck again. The history of ransom payments can be used against you in ransomware victim considerations and target selection.

This puts businesses in a catch-22 situation: cave in now and potentially brace themselves for more attacks, or refuse and risk permanent data loss or operational shutdown. When you are in such a difficult position, you can’t make hasty decisions without evaluating what is in your organization’s best interest. That said, you should always explore other options before resorting to ransom payments.

Legal Implications of Paying Ransoms

Legal controversy exists as to whether ransomware demands should be fulfilled. On the one hand, you’re not violating federal law if you decide to pay to get back on the business track. On the other hand, several states, including North Carolina and Florida, have banned ransomware payments and communication with perpetrators. This controversy is bewildering for organizations grappling with the question of whether to comply with ransom demands or follow state laws that prohibit such practices.

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has its own regulations regarding ransom payments. OFAC prohibits organizations from making payments to sanctioned individuals or entities. If an organization inadvertently yields to pressure from the threat actor that is on OFAC’s sanctions list, it could face severe civil penalties, which adds another layer of risk to the decision-making process. Often, you don’t even know what jurisdiction the attacker operates in to determine whether your actions contradict the OFAC regulations and will result in legal implications.

Meanwhile, the Federal Bureau of Investigation (FBI) takes a position that is somewhere in between government policies on ransomware payments. The Bureau does not outright ban them but strongly advises against such practices. The FBI acknowledges the difficulty some organizations may encounter in the aftermath of an attack and does not recommend imposing a nationwide ban on ransom payments. The reason for this stance is that there’s a risk that putting a legal end to those payments would not ward off attacks and drive negotiations underground.

Ransom Payments Can Be Justified

While transferring the requested funds to ransomware gangs is generally not recommended, there are instances where it may be a necessary evil. Paying the ransom may be the most pragmatic approach when the cost of recovery outweighs the cybercriminal’s demand or when there’s no other way an organization can survive.

One scenario in which giving in might be justified is when a company faces the threat of a class-action lawsuit or irreparable financial loss due to a prolonged outage. For example, an organization that collects plenty of customer data or uses real-time data processing systems may suffer untold reputational and financial damage if the ransom is not paid quickly and customer data is leaked. This is when the cost of a lost business exceeds the perpetrator’s demand, making the payment more of a calculated business decision than a deliberate breach of regulations or capitulation.

A cost-benefit analysis of paying ransoms is a practical method of determining whether doing what the threat actor expects you to do is the lesser of two evils. Analysts and incident response teams must be involved to scrutinize the costs of short-term and long-term ramifications of such a decision.

In the U.S., organizations can apply for cyber insurance and ransomware protection policies to make sure they won’t have to cover the ransom demand on their own if under attack. However, cyber insurance policies are ever-changing as new laws come into effect to fight ransomware operations.

What Should You Do If You Decide to Pay?

If an organization is contemplating a ransom payment, it should adhere to critical steps to minimize the blast radius:

  1. Report the incident. If under attack, companies should notify the FBI’s Internet Crime Complaint Center (IC3) and local law enforcement groups of the incident. Not only is reporting useful for the IC3 to keep track of ransomware attacks and prosecute threat actors, but it can also help you deal with the incident.
  2. Contact your insurance provider. If you have a cyber insurance and ransomware protection plan, involve your insurance company as soon as the attack is detected. The failure to notify your insurer early enough may lead to ransom reimbursement denial later.
  3. Hire a ransomware negotiator. There are specialists who are well-versed in ransomware negotiation ethics and have professional negotiation skills to protect your organization’s interest when dealing with online gangs. You can hire them as an incident response team or ask your insurance provider whether they have negotiators.
  4. Negotiate the amount requested. The ransom demand is not set in stone. It’s just business for threat actors who may be willing to reduce the amount to make sure they are getting paid. Negotiating ransom demands can also buy your organization more time to align efforts with law enforcement groups and prepare your recovery strategy.
  5. Test the decryption key. If the decision is made to pay the ransom, ask the attacker for proof that their decryption key can actually decrypt your files before sending any money. Some ransomware gangs intentionally share incomplete or ineffective decryption keys that will do no good to your network.
  6. Implement a recovery plan. Don’t wait until the incident is settled. Start recovering the affected files, beefing up data storage systems, and updating your cybersecurity while negotiating with the perpetrator.

The decision to pay or not to pay a ransom is complex. However, if a cost-benefit analysis shows you are better off agreeing to the online gang’s demand, the least you can do to mitigate the long-term impact of ransom payments is to follow these steps.

To minimize any risk of having to deal with malicious software and ransoms, invest in proven cybersecurity measures. Ransomware prevention solutions offered by Spambrella can help businesses avoid extortion situations and the tough decision of whether or not to pay a ransom.

 

Additional reading:

Ethical Phishing: Testing Your Employees

Hackensack Meridian Health Pays Attackers Ransom

Contact Sales