Posted in

Should You Actually Pay Ransomware Attackers? What Experts Say

Should You Actually Pay Ransomware Attackers? What Experts Say

A small manufacturing company I read about last year got hit on a Friday night, every file server encrypted, a countdown timer on the ransom note ticking toward a price that doubled after 72 hours. They paid. The decryption key worked, mostly, except for a chunk of corrupted files that never came back, and six months later they got hit again by a different group who’d apparently bought their info off the first attacker’s dark web listing. That second part isn’t rare, and it’s the piece most “should I pay” articles skip over entirely.

The short answer federal agencies give is consistent: don’t pay. The real answer, for anyone actually staring at a ransom note, is more complicated than a one-line recommendation, because the consequences of not paying can be genuinely catastrophic depending on what’s encrypted and who you are.

Quick Answer

  • The FBI and CISA officially recommend against paying. CISA’s joint guidance with the FBI is explicit that payment doesn’t guarantee file recovery and can fund further criminal activity.
  • Paying doesn’t guarantee you get your data back or that it stays private. Working decryption tools, complete data return, and no future leak are all things attackers can simply fail to deliver even after payment.
  • The decision in practice usually comes down to backups. Organizations with solid, tested, offline backups rarely need to seriously consider paying; organizations without them face a much harder real-world calculation than the official guidance accounts for.

Why Experts Recommend Against Paying

The core argument against payment isn’t really about any individual victim’s situation, it’s about the incentive structure paying creates across the entire threat landscape. Every successful payment confirms that a target’s ransom demand was collectible, which keeps ransomware profitable as a business model and funds the next attack against someone else.

There’s also a practical trust problem baked into the transaction itself. You’re negotiating with a criminal organization that has no legal obligation to deliver anything, and the “reputation” some ransomware groups try to maintain for actually decrypting files after payment is entirely self-interested rather than any kind of guarantee. Some groups do generally deliver working decryptors because it’s better for their long-term extortion business if victims believe payment works; others take the money and vanish, or hand over broken or partial decryption tools.

[COMMON TRAP] A lot of people assume that once you pay and get a decryption key, the incident is essentially over. In reality, the attacker typically still has a full copy of whatever data they exfiltrated before encrypting it, and paying for a decryption key does nothing to guarantee that stolen data won’t be sold, leaked, or used for a second extortion attempt later. Many modern ransomware groups run a “double extortion” model specifically because encryption alone stopped being enough leverage — they steal the data first, then encrypt it, so payment for decryption doesn’t address the separate threat of the data being published regardless.

What Actually Happens If You Pay

Setting aside the ethical and policy argument, here’s the more mechanical reality of what a payment typically involves, since most public guidance skips the operational detail.

Negotiation usually happens first. Initial ransom demands are frequently set high with the expectation of negotiation, and specialized ransomware negotiation firms exist specifically to handle this process, often reducing the final payment substantially from the opening demand.

Payment is almost always in cryptocurrency, typically Bitcoin or Monero, sent to a wallet address the attacker controls, making the transaction difficult to trace and functionally impossible to reverse once sent.

A decryption tool, if delivered, still requires real technical work to apply. Decryption isn’t instant or guaranteed to be clean — corrupted files, partial recovery, and lengthy decryption runtimes on large datasets are all common even in cases where the tool genuinely works as intended.

Some jurisdictions add a legal complication. In the U.S., paying a ransom to an entity on a sanctioned persons list maintained by the Treasury’s Office of Foreign Assets Control can itself expose the paying organization to legal liability, regardless of the ransomware circumstances, which is part of why many organizations involve legal counsel before making any payment decision.

[PRO TIP] If your organization is even considering payment, involve legal counsel and, where required, notify law enforcement before making any decision, not after. Beyond the sanctions risk mentioned above, cyber insurance policies frequently have specific notification requirements and pre-approved negotiation vendors, and skipping that process can jeopardize coverage for the incident entirely, on top of whatever the ransom itself costs.

When Backups Change the Calculation Entirely

The single biggest factor separating organizations that never seriously consider paying from those that feel they have no choice is the state of their backups going into the attack.

Offline, immutable, regularly tested backups mean a ransomware attack becomes primarily a recovery-time problem rather than a data-loss problem. Restoring from backup can still take days depending on scale, but it sidesteps the entire payment decision, the trust problem, and the sanctions risk in one move.

Organizations without that safety net face a fundamentally different and harder decision, one where “just restore from backup” simply isn’t an option and the realistic choices are pay, rebuild from scratch, or accept permanent data loss. This is exactly why ransomware prevention guidance from CISA and similar agencies emphasizes backup strategy so heavily — it’s the single control that most directly removes the payment dilemma before it ever comes up.

Comparison: Paying vs. Not Paying

FactorPaying the RansomNot Paying
Data recovery guaranteeNone — decryption may fail, be partial, or never arriveDepends entirely on backup quality and testing
CostRansom amount plus negotiation/legal feesRecovery/rebuild cost, potential downtime cost
Legal riskPossible sanctions exposure depending on the group paidNone from the payment itself
Data leak riskStolen data may still be leaked or sold regardlessSame risk, unaffected by the payment decision
Future targeting riskMay mark the organization as a “payer” for future attacksNo confirmation to attackers that extortion works

Pros and Cons

Paying

  • Pros: Potential faster path to file recovery if no viable backup exists, may reduce operational downtime in a genuine no-backup scenario
  • Cons: No guarantee of actual recovery, funds future criminal activity, possible legal/sanctions exposure, doesn’t prevent stolen data from being leaked separately

Not Paying

  • Pros: No sanctions risk, doesn’t fund the criminal ecosystem, aligns with law enforcement guidance
  • Cons: Requires solid backups to be a realistic option, can mean permanent data loss without them, recovery may still take significant time

Troubleshooting Weird Reality

Backups exist, but they were also encrypted or deleted during the attack. This is one of the most common ransomware attack patterns specifically because attackers know backups are the thing that makes their leverage disappear. Modern ransomware frequently targets connected backup systems deliberately, which is why offline or immutable (write-once) backup copies that an attacker’s initial network access genuinely cannot reach matter more than simply having backups that exist somewhere on the same network.

Paid the ransom, received a decryption tool, and it only decrypts some of the files. Partial or buggy decryption tools are a known and fairly common outcome, not necessarily a sign the attacker deliberately shortchanged the payment. Ransomware encryption and decryption processes can fail on specific file types, especially very large files or files that were mid-write when encryption occurred, and this is generally treated as an expected risk of the payment process rather than a solvable problem after the fact.

Decided not to pay, restored from backup, and got hit by the same group again within months. If the original intrusion vector (how attackers initially got in) wasn’t identified and closed during incident response, restoring from backup brings systems back online without necessarily fixing the underlying vulnerability that let the attacker in the first place. A full post-incident forensic review focused specifically on the initial access point, not just data recovery, is the step that gets skipped most often under the pressure to get systems back online quickly.

Frequently Asked Questions

Is it illegal to pay a ransomware attacker in the United States? Not automatically, but it can become illegal if the payment goes to an entity or individual on a U.S. Treasury sanctions list, which is why involving legal counsel before payment is strongly recommended rather than optional.

Does cyber insurance typically cover ransomware payments? Many cyber insurance policies do cover ransom payments as part of a broader incident response package, though coverage details, notification requirements, and pre-approved vendor requirements vary significantly by policy and insurer.

If I pay, will the attacker actually delete the stolen data as promised? There’s no reliable way to verify this, and there have been documented cases of ransomware groups claiming to delete data after payment while retaining or later leaking it regardless.

Do ransomware negotiators actually reduce the payment amount? Frequently, yes. Initial demands are often set with room for negotiation built in, and specialized negotiation firms with experience in this specific process regularly secure meaningfully lower final payments than the opening ask.

Is a small business more or less likely to get its data back after paying compared to a large company? There’s no reliable public data suggesting a consistent difference by company size; recovery success depends more on which specific ransomware group and encryption method was used than on the size of the victim organization.

What should a company do first if it discovers a ransomware attack in progress? Isolating affected systems from the network to limit spread, preserving evidence for forensic investigation, and contacting law enforcement (such as the local FBI field office) and legal counsel early are generally the first recommended steps, before any decision about payment is even considered.

Wrapping Up

Federal guidance is consistent and clear: don’t pay, because payment doesn’t guarantee recovery and funds the broader ransomware economy. In practice, that guidance is far easier to follow for organizations with solid, tested, offline backups than for the ones without them, which is exactly why backup strategy is the piece of ransomware defense that matters more than almost anything else discussed after an attack has already happened. If you’re evaluating your own defenses before an incident forces the question, the CISA and FBI joint ransomware guidance is worth reviewing directly rather than relying on secondhand summaries of it.

Alex Carter is a hardware geek, macOS enthusiast, and freelance tech troubleshooter. Having spent over a decade tearing down gaming consoles and optimizing custom PC builds, he specializes in bridging the gap between console peripherals and Apple ecosystems. When he’s not fixing Bluetooth latency on MacBooks, he’s probably losing his soul in Elden Ring. Check out his full gaming history on Backloggd or his professional background on LinkedIn.
Looking for more information about this project?
You can learn more about the philosophy, mission, and goals of MobiGG on the About Us page.

Leave a Reply

Your email address will not be published. Required fields are marked *