Victim Q&A · Ransom & cost
Should we pay the ransom after a ransomware attack?
Short answer
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
Key points
- Paying is not getting data back: in Cybereason's 2024 survey only 47% of companies that paid recovered their data and services uncorrupted.
- Paying is not deletion: when the UK NCA took over LockBit's infrastructure in February 2024 it found data belonging to victims who had paid.
- Payers get remembered: 78% of paying companies in the same survey were held to ransom again, and 63% were asked for more the second time.
- The compliance risk is real: virtual currency exchange is a prohibited business activity in mainland China, and US or UK nexus brings sanctions exposure.
- China's Ministry of Public Security warned in September 2026 against trusting online decryptors and decryption agents, and against paying lightly.
- A decryption service may simply pay the attackers and add a margin: demand a technical explanation, test on files you choose, and put no-payment terms in the contract.
In this order
What to do now
Contain first, and ignore the countdown
Price increases after a deadline and threats to destroy the key are pressure scripts. Follow the order in what to do after a ransomware attack: isolate without powering off, and preserve the ransom note and encrypted samples. Do not reply to the attacker's email or log in to their negotiation page - contact alone confirms you are a staffed, funded target.
Identify the family and version
You cannot weigh payment without knowing who you are dealing with. Use the note filename, the extension and samples with the identification tool, then check whether a public decryptor exists for that build (see which decryption tools exist). If a working public tool covers your version, paying makes no sense at all.
Inventory every data source that bypasses the attacker
Beyond the backup software, check storage array and NAS volume snapshots, hypervisor snapshots and clones, off-site or cloud copies, offline media, local copies on staff endpoints, and the same data held in downstream systems. If the backup server was wiped too, see backups deleted or encrypted.
Put a number on what can be recovered without paying
A decision needs facts, not instinct. A recoverability assessment states which systems can be restored, to what point in time, what is definitively lost and roughly how long it takes. The initial conversation and first read on the family are free; how cost and time are built up is covered in ransomware recovery cost and time.
Assess data theft as a separate question
Encryption and exfiltration are different problems. Buying a decryptor does nothing about a leak threat, and paying for deletion cannot be verified. For scoping the leak, notification duties and external communication, see when attackers threaten to publish data.
Decide with management, legal and compliance, in writing
A ransom is not an expense IT can approve alone. It touches the source and destination of funds, internal approvals and disclosure, and any overseas business, US dollar clearing or US-connected party adds sanctions risk. Keep the assessment, each party's view and the final decision in writing - audits and insurance claims will need them.
Report it, whatever you decide
File with the local public security bureau (the police) in China as early as possible; how to report ransomware to the police lists the materials. In the United States the FBI likewise urges victims to report to IC3 whether or not they pay.
Avoid making it worse
Do not
- Do not decide to pay on the day, under countdown pressure. Until the family is identified and data sources are inventoried, there is not enough information to answer the question.
- Do not let staff buy cryptocurrency from informal dealers or open overseas exchange accounts in their own names to move the money. That route has no legal protection, offers no recourse if it goes wrong, and drags individuals into the organisation's compliance problem.
- Do not treat the attacker's free test decryption as proof that everything will decrypt. Tests are usually limited in file count and size and often exclude databases and backups - and large files, databases and virtual disks are exactly where decryptors fail.
- Do not hand the ransom note, samples or the attacker's contact details to an unknown decryption agent, and never pay a deposit up front. China's Ministry of Public Security specifically warns about being defrauded a second time.
- Do not clean up, delete the note or reinstall systems to prepare for negotiation. Losing that evidence damages the police report, forensics and recovery alike.
- Do not assume that paying means you can skip finding the entry point and rotating credentials. With the door still open, a payment record makes you a priority target for the next attack.
Why do organisations still pay?
Start with an honest fact: plenty of organisations pay. Sophos's State of Ransomware 2026 surveyed 2,158 IT and security leaders in 17 countries and found that 48% of organisations whose data was encrypted paid the ransom. Cybereason's 2024 study of 1,008 enterprises with at least 500 employees that had been held to ransom put the figure higher still, with 84% saying they had paid.
The reasons respondents gave are practical ones: no usable backups, fear of losing business, threats to publish sensitive information, an attack landing on a holiday or weekend when staff were short, and a sense that paying was simply the fastest way out. For a company whose production line has stopped while customers chase deliveries, that pressure is real, and we will not pretend otherwise.
But why people pay and whether paying solves the problem are separate questions. Almost every reason above rests on one assumption: after payment the data comes back, the leak stops and the incident is over. The sections below test that assumption against public evidence.
Our own position is clear - we do not pay ransoms, negotiate on a client's behalf, or buy or transfer cryptocurrency - but the decision is yours. Our job is to make sure it rests on facts.
If we pay, will the data definitely come back?
Not necessarily, and the gap is wider than most people expect. The FBI puts it plainly: paying does not guarantee you will get any data back, and some victims who paid never received a decryption key.
Even with a decryptor in hand, problems are common:
- The decryptor can be broken. In December 2019 Emsisoft disclosed that the updated decryptor Ryuk supplied to paying victims contained a calculation error: on partially encrypted files larger than 54.4 MB it cut off one byte too many at the end. VHD and VHDX virtual disks and database files such as Oracle's keep important information in exactly that position, and failed to load after decryption.
- What comes back is incomplete. In Cybereason's 2024 survey only 47% of companies that paid got their data and services back uncorrupted.
- Decryption takes time as well. The tool has to be run against every affected host and data set. Decrypting, verifying and bringing back dozens of hosts and terabytes of data is still work the organisation must organise, so downtime does not vanish because a payment was made.
The other promise is deletion of stolen data. In February 2024, after Operation Cronos led by the UK National Crime Agency took control of LockBit's infrastructure, the NCA stated that some of the data on LockBit's systems belonged to victims who had paid - evidence that payment does not guarantee deletion, whatever the criminals promised.
Then there is the idea that paying ends it. In the same Cybereason survey, 78% of companies that paid were held to ransom again, and 63% said they were asked to pay more the second time. Payment closes no entry point; it only proves the organisation will pay.
| What the attacker promises | What public evidence shows |
|---|---|
| Pay and the decryptor arrives | FBI: payment does not guarantee data back, and some payers never got a key |
| The decryptor restores everything | Ryuk's decryptor truncated large files; only 47% of payers recovered uncorrupted data |
| Stolen data is deleted after payment | The NCA found paying victims' data on LockBit's systems |
| You will not hear from them again | 78% of paying companies were held to ransom again |
What are the legal and compliance risks of paying?
What follows summarises published rules and official guidance. It is not legal advice; rely on the competent authorities and your own counsel.
In mainland China. On 6 February 2026 the People's Bank of China and seven other authorities issued the Notice on Further Preventing and Handling Risks Related to Virtual Currencies (Yinfa [2026] No. 42), which repealed the 2021 notice (Yinfa [2021] No. 237). It restates that virtual-currency business activities in China, including exchange between fiat and virtual currency, are illegal financial activities and strictly prohibited; that financial institutions, including non-bank payment institutions, must not provide account opening, fund transfer or clearing and settlement services for them; that civil acts by any organisation or individual investing in virtual currency contrary to public order and good morals are void; and that fraud, money laundering and other crimes involving virtual currency are to be pursued under the law.
The notice is not written about ransoms, but the practical meaning is clear. Turning yuan into bitcoin or USDT to pay a ransom can realistically only happen through prohibited exchange channels or overseas platforms, with no recourse if anything goes wrong. State-owned entities, listed companies and regulated sectors usually have their own rules on expenditure, disclosure and incident reporting, and workarounds such as an individual advancing the money for later reimbursement can create a bigger problem at audit. The Ministry of Public Security's cyber security bureau also lists not paying a ransom lightly among the three don'ts in its September 2026 advisory.
US nexus. The US Treasury's Office of Foreign Assets Control (OFAC), in its updated advisory of 21 September 2021, states that the US government strongly discourages paying ransoms. Payments to sanctioned persons or comprehensively embargoed jurisdictions can violate sanctions, and OFAC may impose civil penalties on a strict liability basis - a person can be liable without knowing the recipient was sanctioned. The advisory names financial institutions, cyber insurers and digital forensics and incident response firms that facilitate payments on behalf of victims as also at risk, and treats a self-initiated, timely and complete report to law enforcement, plus cooperation, as mitigating factors. OFAC has designated a number of ransomware-linked individuals and groups, and virtual currency exchanges that moved ransom proceeds, such as SUEX in September 2021.
UK nexus. The Office of Financial Sanctions Implementation's guidance on ransomware and financial sanctions (updated January 2026) states that the UK government does not condone paying ransoms; that making funds available to an asset-freeze target through a ransom is a breach of financial sanctions and a serious criminal offence that can carry a custodial sentence or a monetary penalty; and that ransomware payments are unlikely to be considered appropriate for an OFSI licence. Where victims report through the national cyber incident portal, voluntarily disclose to OFSI and cooperate with law enforcement, OFSI and the NCA are more likely to resolve a case without a monetary penalty or criminal investigation.
Foreign-invested companies in China, and any business with an overseas parent, US dollar settlement or a US-connected party, should bring legal and compliance in before any conversation about payment begins.
What are decryption brokers, and how do you spot one?
Some services market themselves as ransomware decryption or recovery without paying, but what they actually do is contact the attackers on the victim's behalf, pay the ransom, obtain the decryptor, and bill the victim for the ransom plus a fee.
This is documented, not speculation. In May 2019 the US non-profit newsroom ProPublica investigated two US data recovery firms that claimed to decrypt with their own technology. Proven Data Recovery's CEO acknowledged that paying attackers was standard procedure, and ProPublica traced four of its ransom payments to SamSam on the blockchain - wallets the US Treasury later placed under sanctions. The other firm, MonsterCloud, told visitors not to pay the ransom, yet quoted one client US$25,000 where the underlying ransom was about US$7,000. In China, the first of the three don'ts in the Ministry of Public Security's September 2026 advisory is not to trust online decryption tools or decryption agents, to avoid being defrauded twice.
A broker that pays on your behalf passes every risk in the previous sections straight through to you. The decryptor can still be broken, deletion is still unverifiable and the money still reaches the attackers - only at a higher price, and possibly without you knowing a ransom was paid at all. Useful tests:
| What to ask or look at | What genuine technical recovery looks like | Warning signs |
|---|---|---|
| Why recovery is possible | A clear path: a named public decryptor and the builds it covers, a known implementation flaw, repair of intermittently encrypted files, backups and snapshots | A proprietary algorithm or inside channel, or claims to crack the newest builds of families with no public tool |
| What they need from you | The ransom note and a few encrypted samples for identification | The contact details, victim ID or negotiation page address from the note |
| How timing is set | Estimated from data volume and repair difficulty | Depends on when the other side replies |
| How the price is set | A written quote based on assessed effort | A price that moves with the ransom amount, or a percentage of it |
| How they get paid | Corporate bank account with invoices | Personal accounts or cryptocurrency only, or full payment or a deposit up front |
| What the contract says | Scope, deliverables, acceptance criteria and what happens if recovery fails | Only verbal promises of 100% decryption or guaranteed recovery |
How a test decryption is run matters. Attackers themselves offer to decrypt a few files for free, so a provider that decrypts a handful of your samples has only shown it can get the key - not that it did not pay for it. Stronger evidence: you choose the files, including large files and databases; the provider explains how the decryption works; and the contract states that no contact will be made with, and no payment made to, the attackers. A provider willing to sign that clause at least has confidence in its own technical route.
How else can data be recovered without paying?
Not paying does not mean giving up on the data. Recoverability varies with the family, version, encryption method and state of backups, and the usual paths are:
- Public decryptors. For a small number of families, leaked keys, law enforcement seizures or implementation flaws have produced decryptors published by police agencies or security vendors. They usually work only for specific builds and must be matched before use.
- Backups, snapshots and off-site copies. In Sophos's 2026 survey, 66% of organisations whose data was encrypted recovered through backups. Storage and hypervisor snapshots are often administered separately from the backup system and are frequently overlooked.
- Database and virtual disk repair. Many families encrypt only the start of large files or encrypt intermittently, leaving most data pages and disk regions intact and readable business data extractable - see database encrypted by ransomware.
- Remnants and downstream data. Remnants in unallocated space, copies on staff endpoints, and the same records in connected systems.
Which path works, and how far it gets you, can only be established by assessing read-only copies; the overall reasoning is in can encrypted files be recovered.
Recovery is half the job. The other half is finding the entry point, removing back doors and rotating every credential - otherwise you can be encrypted again whether or not you paid. See why ransomware keeps coming back and our incident response service.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related questions
- Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- Aftermath
A ransomware gang is threatening to publish our data - what should we do?
Do not respond or pay yet. First establish with evidence whether data actually left and what it was: check outbound traffic, archive staging, transfer tools such as Rclone, MEGA or WinSCP, and cloud sign-in and export logs, and compare any samples the attackers released against your own data - some threats are bluffs or recycled old leaks. Paying does not buy deletion: the UK's National Crime Agency found data belonging to victims who had paid still on LockBit's systems. Close the exfiltration path, rotate credentials, and assess notification duties under the PIPL and related rules.
- Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
- Recovery
Which ransomware decryption tools exist, and are downloaded ones safe to use?
Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
Related solutions
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
Related services
Ransomware Decryption
Identify the family first, then commit to a recoverable scope — without paying a ransom.
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
FAQ
Follow-up questions
The attackers offer to decrypt a few files for free - does that mean everything will decrypt if we pay?
No. Free test decryptions are usually limited in number and size and often exclude valuable files such as databases and backups, so all they prove is that the attackers hold the matching private key. Failures happen precisely outside that scope - in large files, databases and virtual disks. In the Ryuk case Emsisoft disclosed, the decryptor's bug only affected partially encrypted files over 54.4 MB, leaving VHD, VHDX and Oracle database files unloadable after decryption - exactly the kind of file a test never covers. Sending samples or uploading them to the attacker's page is also a form of contact that tells them you are considering payment.
Can the ransom be negotiated down?
Negotiation is common: in Sophos's 2026 survey, 51% of organisations that paid ended up paying less than the initial demand. But negotiating means you are already in the payment process - contact, bargaining, payment, waiting for a decryptor - and none of the risks above shrink because the amount did. We do not negotiate on a client's behalf, and we advise against making contact just to test the price. That time is better spent inventorying backups and snapshots and establishing how much can be recovered without the attackers.
We have already paid. What now?
Payment does not close the incident. These steps still matter:
- Back up the encrypted data before running any decryptor. This was Emsisoft's advice after the Ryuk case: a faulty decryptor rewrites files directly, and without a copy there is no way back. Check the attacker's decryptor in an isolated environment first to make sure it carries nothing else.
- Report it and keep the payment records. Transaction times, amounts, wallet addresses and chat and email records are all evidence; the FBI also urges victims to report whether or not they paid.
- Find the entry point, remove back doors and rotate every credential. Paying patched nothing, and with the door open the next demand may come sooner.
- Expect further demands. Do not give way to new requests such as paying again to have data deleted, and assess the data exposure separately.
Is it illegal for a company in China to pay a ransom in bitcoin or USDT?
That is for legal counsel to judge on the facts, and we do not give legal advice. The public facts are these: Yinfa [2026] No. 42, issued in February 2026, restates that virtual-currency business in mainland China, including fiat-to-crypto exchange, is an illegal financial activity; that financial institutions and non-bank payment institutions must not provide account opening, fund transfer or clearing services for it; and that civil acts investing in virtual currency contrary to public order and good morals are void. The channels you would rely on to buy and move coins for a ransom therefore have no legal protection and offer no recourse, and the company's own approval, audit and disclosure obligations come into play as well. The Ministry of Public Security's advice is not to pay lightly and to report to the local police immediately. For a definitive view, consult the authorities and your counsel.
If the company decides to pay anyway, what can NoRansom still do?
We take no part in anything connected to a transaction with the attackers: no contact, no negotiation, no buying or transferring cryptocurrency, and where a client transacts with an attacker independently the risks and consequences rest with the client. The technical work is still needed alongside that: preserving evidence and producing a forensic report, establishing the entry point and the extent of compromise, removing back doors and persistence, assessing which data can be recovered without the attackers, and hardening afterwards. The assessment also shows management how much data genuinely depends on the attackers.
Sources
- 文件加密、索要赎金!勒索病毒来了,这份企业防护指南请收好(2026-09-04,「两要三不要」:不要轻信解密代理、不要轻易支付赎金)— 公安部网安局 / 中国新闻网
- NCA leads international investigation targeting world's most harmful ransomware group(2024-02-20,LockBit 系统中存有已付款受害者的数据)— UK National Crime Agency
- Ransomware: The True Cost to Business 2024(1,008 家企业;84% 付款、47% 拿回未损坏数据、78% 再次被勒索)— Cybereason
- The State of Ransomware 2026(2,158 名受访者、17 国;48% 被加密组织付款、66% 通过备份恢复、51% 付款低于要价)— Sophos
- Caution! Ryuk Ransomware decryptor damages larger files, even if you pay(2019-12-09)— Emsisoft
- Ransomware(FBI 不支持支付赎金;无论是否付款都应向 IC3 报告)— FBI
- Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments(2021-09-21,严格责任与减轻处罚因素)— U.S. Treasury OFAC
- Financial sanctions guidance for ransomware(2026-01-28 更新)— UK OFSI / GOV.UK
- 中国人民银行等八部门关于进一步防范和处置虚拟货币等相关风险的通知(银发〔2026〕42 号,2026-02-06,同时废止银发〔2021〕237 号)— 中国人民银行
- The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers(2019-05-15)— ProPublica
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated