UK Proposes Ransomware Payment Ban for Public and Critical Infrastructure Sectors
Articles by the same author:
1
2
3
4
The UK government announced on July 22, 2025, its intention to prohibit public sector bodies and operators of critical infrastructure from paying ransoms to cybercriminals following ransomware attacks. In addition, the Home Office and the National Cyber Security Centre (NCSC) are considering new rules that would compel private-sector organizations not covered by the ban to notify authorities before making any ransom payment.
While paying a ransom is not currently illegal in the UK, it is prohibited to send money to sanctioned entities—most of which are Russian-linked cybercriminal groups. The NCSC strongly advises against paying ransoms, stressing that such payments do not guarantee data recovery or systems access, while also funding organized crime and incentivizing further attacks.
The UK is also considering making ransomware incident reporting mandatory across all sectors, with penalties for non-compliance.