According to our 2025 State of the Underground report, ransomware attacks rose by nearly 25% in 2024, and the number of ransomware group leak sites jumped 53%. This surge sets the stage for a critical question: if compromised, should you pay ransomware demands or not? The stakes are enormous, including downtime, data loss, brand damage, and legal risk all hang in the balance. Choosing not to pay can send a message that your organization will not give in, potentially making you a less attractive target in the future. But the trade-off can be brutal—losing access to your data, exposing sensitive information, facing regulatory penalties, massive financial losses, and dealing with major reputational and operational fallout. View the latest ransomware stats on Underground Explorer.
As Stephen Boyer, Co-Founder and Chief Innovation Officer at Bitsight, has pointed out, “What’s clear is that these attackers are targeting known vulnerabilities … It’s no longer just an IT problem. A company’s security is starting to have a growing impact over key parameters such as insurance rates, stock price, and board votes.”
The global debate over whether to pay ransom has only intensified as governments take stronger stances. The UK’s recent decision to ban ransom payments for public sector organizations, for instance, reflects a growing desire to break the business model of ransomware groups. As Stephen Boyer noted in his commentary on the ban, prohibitions are symbolically powerful but rarely sufficient on their own. Attackers adapt quickly, shifting tactics and targeting private organizations instead. Real progress comes from prevention — actionable intelligence, visibility, and resilience — rather than from bans or blanket policies.
What are the different levels of extortion?
Ransomware groups have evolved far beyond simply locking files. Today, there are several levels of extortion designed to maximize pressure on victims:
- Single extortion is the original model, where attackers encrypt data and demand payment for a decryption key.
- Double extortion adds a layer of pressure by stealing data before encrypting it and threatening to leak it publicly if the ransom isn’t paid.
- Triple extortion expands the impact even further, with attackers reaching out directly to customers, partners, or employees, or launching Distributed Denial of Service (DDoS) attacks to intensify the disruption.
- Some groups take things even further with quadruple extortion, combining all previous tactics with threats like stock manipulation, false reports to regulators, or targeted harassment of executives.
- Newer campaigns have introduced multi-extortion methods, blending various techniques in unpredictable ways to keep victims off balance.
- There’s also a growing trend of email extortion, where attackers use stolen data to send direct threats to individuals within or outside the organization, aiming to embarrass the company and escalate pressure to pay.
The case for paying ransom
There are several reasons some organizations decide to pay. When backups are unavailable or compromised, paying can be the fastest path to recovery and resuming operations. After an attack, the pressure to get back online is intense, especially from leadership and stakeholders who want business as usual restored as quickly as possible. Paying can sometimes minimize downtime and the financial fallout that comes with prolonged disruption. In highly targeted industries like manufacturing, every hour of downtime can ripple across customers and partners, much like the global semiconductor shortage during the COVID-19 pandemic, which brought production in automotive and electronics to a standstill. In some cases, organizations that refused to pay ended up spending far more on recovery than the original ransom demand. In manufacturing, time truly is money, and every minute of halted production can translate directly into lost revenue.
Paying can also help avoid public exposure, embarrassment, or legal consequences if attackers are threatening to leak sensitive information. As Boyer pointed out in his discussion of the UK ransomware ban, outright prohibitions remove the ability to make a rational business decision. In some situations, paying may be the least damaging financial path, especially when recovery costs and reputational fallout exceed the ransom itself.
Threat insight: Bitsight Threat Intelligence (TI) can help assess whether the actor is known to honor payments or has a history of double extortion, getting paid and then leaking data anyway.
The case against paying ransom
Paying the ransom comes with real risks. There is no guarantee the attackers will deliver what they promise. In many cases, victims have paid only to receive a broken decryption key or nothing at all.
Even when a key is provided, decryption tools do not always work as intended. Files can still be corrupted or only partially restored, leaving organizations paying for an incomplete fix.
Every payment also fuels the ransomware economy, reinforcing the idea that these attacks pay off. That money often funds future operations and keeps the criminal ecosystem alive.
Legal and compliance risks are another serious concern. Paying could violate laws if the attackers are linked to sanctioned groups, and in regulated industries, this can result in fines or investigations. According to the HIPAA Journal, roughly 71 percent of ransomware victims choose not to pay, often after weighing these very risks.
While not paying may seem appealing from a morality standpoint, it often costs the victims more in recovery efforts and down time than the initial ransom demand. Still, as the UK’s stance reflects, payment bans aim to break the financial incentive that fuels these attacks. Whether that approach will prove effective remains to be seen. Ransomware groups are resilient businesses in their own right, adapting quickly to maintain profit.
Threat insight: Bitsight can provide threat actor attribution and flag if the group is under sanctions, helping organizations avoid inadvertent legal violations.