The UK National Cyber Security Centre issued guidance urging organisations hit by ransomware to avoid panic and carefully assess alternatives before paying attackers, including restoring from backups or using available decryptors. The guidance, developed with insurance bodies ABI, BIBA, and IUA, says victims should document decisions, involve insurers, law enforcement, incident response providers, and internal technical teams, and investigate the root cause to prevent repeat compromise. It also warns that paying a ransom does not guarantee data recovery, deletion of stolen data, or compliance with legal and regulatory duties, and may be unlawful where sanctions apply.
The guidance aligns with a broader UK policy debate as officials advance plans to bar public sector bodies and critical national infrastructure operators from making ransom payments. Reporting on the debate says ransomware attacks are becoming more sophisticated, with some criminal groups using malicious AI tools such as WormGPT, FraudGPT, and BruteForceAI, while many intrusions still succeed through known vulnerabilities and weak security controls. Experts remain split on payment bans, but the reporting and official guidance both emphasize stronger resilience measures such as backups, monitoring, multi-factor authentication, and prompt reporting to authorities, including the NCSC in nationally significant cases.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
According to Fortinet's Dave Spillane, confirmed ransomware victims rose by 389% year-on-year in 2025, increasing from nearly 1,600 cases in 2024 to 7,831 worldwide in 2025. He said attackers could target four organisations in the time it previously took to conduct one attack.
Sophos' 2025 cybersecurity research found that nearly half of organisations hit by ransomware paid cybercriminals to regain access to data or systems. The finding was cited in the context of rising ransom demands and debate over payment restrictions.
The UK National Cyber Security Centre published guidance for organisations considering whether to pay a ransom during a ransomware incident. The guidance was jointly developed with ABI, BIBA, and IUA and advises victims to assess alternatives, involve relevant authorities and experts, and understand that payment does not guarantee recovery or legal compliance.
The UK government is progressing plans to prevent public sector organisations and critical national infrastructure operators from making ransomware payments. The proposed restrictions would apply to entities including the NHS, local councils, and schools.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.