Government may also require private companies to report any ransom payments

The UK government announced on July 22, 2025, its intention to prohibit public sector bodies and operators of critical infrastructure from paying ransoms to cybercriminals following ransomware attacks. In addition, the Home Office and the National Cyber Security Centre (NCSC) are considering new rules that would compel private-sector organizations not covered by the ban to notify authorities before making any ransom payment.

While paying a ransom is not currently illegal in the UK, it is prohibited to send money to sanctioned entities—most of which are Russian-linked cybercriminal groups. The NCSC strongly advises against paying ransoms, stressing that such payments do not guarantee data recovery or systems access, while also funding organized crime and incentivizing further attacks.

The UK is also considering making ransomware incident reporting mandatory across all sectors, with penalties for non-compliance.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.