Pay up or not? Ransomware surge has victims facing tough choices.

Pay up or not? Ransomware surge has victims facing tough choices.

付款还是拒绝?勒索软件激增让受害者陷入两难

Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. 根据网络安全机构 Sophos 2025 年的研究,近半数遭受勒索软件攻击的企业最终会支付赎金以恢复数据或系统,且勒索金额的中位数正在不断攀升。

Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for example, the government is advancing plans to prohibit public sector bodies and critical national infrastructure groups—including the National Health Service, local councils and schools—from making payouts. 在全球范围内,一些司法管辖区正通过禁止向黑客支付赎金来应对这一问题。例如在英国,政府正在推进相关计划,禁止公共部门机构和关键国家基础设施组织(包括国家医疗服务体系、地方议会和学校)支付赎金。

The potential veto comes as ransomware hackers have become more advanced and meticulous in their targeting of companies, particularly vulnerable small and medium-sized businesses, over time. 这一潜在的禁令出台之际,勒索软件黑客在针对企业(尤其是脆弱的中小企业)的攻击中变得愈发先进和缜密。

“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” says Haydn Brooks, chief executive of supply chain security group Risk Ledger. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.” 供应链安全机构 Risk Ledger 的首席执行官 Haydn Brooks 表示:“到 2026 年,勒索软件领域已经演变成一个高度复杂、企业化的生态系统。虽然勒索软件团伙像精明的 B2B 企业一样运作以确保数据返还,但支付赎金所带来的法律和制裁风险正处于历史最高水平。”

This has been powered by the rise of malicious AI hacking tools such as WormGPT, FraudGPT and BruteForceAI, according to Dave Spillane, systems engineering director at Fortinet, who notes that confirmed ransomware victims rose 389 percent year-on-year in 2025, from around 1,600 in 2024 to 7,831 globally. Fortinet 系统工程总监 Dave Spillane 指出,这一趋势是由 WormGPT、FraudGPT 和 BruteForceAI 等恶意 AI 黑客工具的兴起所推动的。他指出,2025 年全球确认的勒索软件受害者人数同比增长了 389%,从 2024 年的约 1,600 例增加到 7,831 例。

“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” he says. 他说:“黑客现在可以在过去发动一次攻击的时间内,同时针对四个不同的组织进行攻击。”

“The cost per attack has dramatically decreased, commoditizing sophisticated attacks, whereas the cost to defend is increasing,” agrees Shashi Kiran, chief marketing officer of tech group Nile. “What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.” 科技集团 Nile 的首席营销官 Shashi Kiran 也表示认同:“单次攻击的成本大幅下降,使得复杂的攻击变得商品化,而防御成本却在增加。过去需要国家级力量才能完成的事情,现在仅凭半吊子技术的个人利用 AI 的力量就能实现。”

Nevertheless, whether to pay out or not remains one of the most divisive areas in cybersecurity. Jim Walter, a senior threat researcher at SentinelOne, says that his cyber security group takes a hard line against responding to ransoms. 尽管如此,是否支付赎金仍然是网络安全领域最具争议的问题之一。SentinelOne 的高级威胁研究员 Jim Walter 表示,他的网络安全团队对支付赎金持强硬的反对态度。

“Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he says, noting that threat actors cannot be trusted to delete data upon payment. Re-extortion and the ongoing monetization of stolen data are commonplace, he adds. “Paying absolutely does not guarantee recovery, it actually encourages further crime and extortion.” “向勒索者支付赎金只会加强这个生态系统及其背后的实体,”他说道,并指出不能指望威胁行为者在收到钱后会删除数据。他补充说,二次勒索和被盗数据的持续变现已是常态,“支付赎金绝对不能保证数据恢复,反而会助长更多的犯罪和勒索行为。”

Others are less absolute. “Our concern with a ban is what happens when a payment ban is in place but data recovery is not feasible,” says Andy Maus, head of cyber recovery services at DriveSavers, which recovers hard drive data. “Situations are almost always more nuanced than a ban accounts for.” 其他人则没那么绝对。专门从事硬盘数据恢复的 DriveSavers 公司网络恢复服务主管 Andy Maus 表示:“我们对禁令的担忧在于,如果实施了支付禁令,但数据恢复又不可行,该怎么办?情况往往比禁令所考虑的要复杂得多。”

When it comes to critical national infrastructure, for example, such as a water utility or power provider, the consequences for customers can be more serious if a ransom cannot be paid but data also cannot be recovered. “We can see how payment bans make sense where data recovery is a viable alternative; however, blanket prohibition has the potential to cause more harm than it prevents,” Maus says. 以关键国家基础设施为例,如供水或电力供应商,如果无法支付赎金且数据无法恢复,对客户造成的后果可能更为严重。Maus 说:“我们理解在数据恢复是可行替代方案的情况下,支付禁令的意义;然而,一刀切的禁令可能会造成比它所预防的更大的伤害。”

He notes that in North Carolina and Florida, where statewide bans were introduced in 2021 and 2022 respectively, “neither ban appears to have materially deterred criminal activity.” 他指出,在分别于 2021 年和 2022 年实施全州禁令的北卡罗来纳州和佛罗里达州,“这两项禁令似乎都没有实质性地遏制犯罪活动。”

Brooks at Risk Ledger warns that without critical national infrastructure payouts, cyber criminals will “aggressively pivot” to the more unregulated private sector. If public bodies are banned from paying, “the cyber insurance market will inevitably shift,” he adds, “excluding these payouts and driving premiums sky-high as the costs dwarf the original ransom demands.” Risk Ledger 的 Brooks 警告称,如果没有关键国家基础设施的赎金支付,网络罪犯将“积极转向”监管较少的私营部门。他补充说,如果公共机构被禁止支付,“网络保险市场将不可避免地发生转变,将这些赔付排除在外,并推高保费,因为其成本将远超最初的赎金要求。”

There is now a growing market of services to support companies in their response to attacks, including ransom negotiators, incident response teams and breach coaches that assess data recovery options. 目前,支持企业应对攻击的服务市场正在不断扩大,包括赎金谈判专家、事件响应团队以及评估数据恢复方案的违规处理顾问。

Maus argues that details such as what data was stolen, whether it involves personally identifiable or sensitive health information, and which threat group is responsible, should all be part of weighing whether data recovery is viable or payment is the right option. Maus 认为,诸如被盗数据的内容、是否涉及个人身份信息或敏感健康信息,以及是哪个威胁团伙所为等细节,都应纳入考量,以权衡数据恢复是否可行或支付赎金是否为正确选择。

But instead of whether to ban payments or not, “the more important question is how to make ransomware less profitable in the first place,” says Gavin Millard, vice-president of product at cyber security company Tenable. Most ransomware attacks still rely on familiar problems such as known vulnerabilities, exposed systems and security gaps, he adds, and the focus should therefore be “exposure management.” 但网络安全公司 Tenable 的产品副总裁 Gavin Millard 表示,比起是否禁止支付赎金,“更重要的问题是如何从源头上降低勒索软件的盈利能力。”他补充说,大多数勒索软件攻击仍然依赖于已知漏洞、暴露的系统和安全缺口等常见问题,因此重点应放在“暴露管理”上。

Walter at SentinelOne says companies need an “awareness of emerging trends in the threat landscape alongside proper technical hygiene” including the continuous monitoring of devices and enforced multi-factor authentication. SentinelOne 的 Walter 表示,企业需要“对威胁形势中的新兴趋势保持敏锐,并保持良好的技术卫生习惯”,包括对设备进行持续监控和强制执行多因素身份验证。

“What you really need is visibility over access to internal systems, and the ability to limit impact once they’re inside,” says Spencer Young, international senior vice-president at access management group Delinea. “Strong controls—like giving employees temporary, on-the-spot permission only when needed—shrink the blast radius and stop ransomware actors from achieving their goals.” 访问管理集团 Delinea 的国际高级副总裁 Spencer Young 表示:“你真正需要的是对内部系统访问权限的可见性,以及在黑客进入后限制其影响的能力。强有力的控制措施——例如仅在需要时给予员工临时的、即时的权限——可以缩小受损范围,阻止勒索软件攻击者实现其目标。”

Others are calling for more innovative support from governments. Rather than prohibiting payment for an attack that has already happened, DriveSavers’ Maus says investing in subsidized backup infrastructure or tax incentives for cybersecurity spending “would do more to reduce the underlying exposure.” 其他人则呼吁政府提供更具创新性的支持。DriveSavers 的 Maus 表示,与其禁止对已经发生的攻击进行支付,不如投资于补贴备份基础设施或为网络安全支出提供税收激励,“这在减少潜在风险方面会更有成效。”