Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Victim Q&A · Ransom & cost

Should we pay the ransom after a ransomware attack?

Short answer

We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.

Key points

  • Paying is not getting data back: in Cybereason's 2024 survey only 47% of companies that paid recovered their data and services uncorrupted.
  • Paying is not deletion: when the UK NCA took over LockBit's infrastructure in February 2024 it found data belonging to victims who had paid.
  • Payers get remembered: 78% of paying companies in the same survey were held to ransom again, and 63% were asked for more the second time.
  • The compliance risk is real: virtual currency exchange is a prohibited business activity in mainland China, and US or UK nexus brings sanctions exposure.
  • China's Ministry of Public Security warned in September 2026 against trusting online decryptors and decryption agents, and against paying lightly.
  • A decryption service may simply pay the attackers and add a margin: demand a technical explanation, test on files you choose, and put no-payment terms in the contract.

In this order

What to do now

  1. Contain first, and ignore the countdown

    Price increases after a deadline and threats to destroy the key are pressure scripts. Follow the order in what to do after a ransomware attack: isolate without powering off, and preserve the ransom note and encrypted samples. Do not reply to the attacker's email or log in to their negotiation page - contact alone confirms you are a staffed, funded target.

  2. Identify the family and version

    You cannot weigh payment without knowing who you are dealing with. Use the note filename, the extension and samples with the identification tool, then check whether a public decryptor exists for that build (see which decryption tools exist). If a working public tool covers your version, paying makes no sense at all.

  3. Inventory every data source that bypasses the attacker

    Beyond the backup software, check storage array and NAS volume snapshots, hypervisor snapshots and clones, off-site or cloud copies, offline media, local copies on staff endpoints, and the same data held in downstream systems. If the backup server was wiped too, see backups deleted or encrypted.

  4. Put a number on what can be recovered without paying

    A decision needs facts, not instinct. A recoverability assessment states which systems can be restored, to what point in time, what is definitively lost and roughly how long it takes. The initial conversation and first read on the family are free; how cost and time are built up is covered in ransomware recovery cost and time.

  5. Assess data theft as a separate question

    Encryption and exfiltration are different problems. Buying a decryptor does nothing about a leak threat, and paying for deletion cannot be verified. For scoping the leak, notification duties and external communication, see when attackers threaten to publish data.

  6. Decide with management, legal and compliance, in writing

    A ransom is not an expense IT can approve alone. It touches the source and destination of funds, internal approvals and disclosure, and any overseas business, US dollar clearing or US-connected party adds sanctions risk. Keep the assessment, each party's view and the final decision in writing - audits and insurance claims will need them.

  7. Report it, whatever you decide

    File with the local public security bureau (the police) in China as early as possible; how to report ransomware to the police lists the materials. In the United States the FBI likewise urges victims to report to IC3 whether or not they pay.

Avoid making it worse

Do not

  • Do not decide to pay on the day, under countdown pressure. Until the family is identified and data sources are inventoried, there is not enough information to answer the question.
  • Do not let staff buy cryptocurrency from informal dealers or open overseas exchange accounts in their own names to move the money. That route has no legal protection, offers no recourse if it goes wrong, and drags individuals into the organisation's compliance problem.
  • Do not treat the attacker's free test decryption as proof that everything will decrypt. Tests are usually limited in file count and size and often exclude databases and backups - and large files, databases and virtual disks are exactly where decryptors fail.
  • Do not hand the ransom note, samples or the attacker's contact details to an unknown decryption agent, and never pay a deposit up front. China's Ministry of Public Security specifically warns about being defrauded a second time.
  • Do not clean up, delete the note or reinstall systems to prepare for negotiation. Losing that evidence damages the police report, forensics and recovery alike.
  • Do not assume that paying means you can skip finding the entry point and rotating credentials. With the door still open, a payment record makes you a priority target for the next attack.

Why do organisations still pay?

Start with an honest fact: plenty of organisations pay. Sophos's State of Ransomware 2026 surveyed 2,158 IT and security leaders in 17 countries and found that 48% of organisations whose data was encrypted paid the ransom. Cybereason's 2024 study of 1,008 enterprises with at least 500 employees that had been held to ransom put the figure higher still, with 84% saying they had paid.

The reasons respondents gave are practical ones: no usable backups, fear of losing business, threats to publish sensitive information, an attack landing on a holiday or weekend when staff were short, and a sense that paying was simply the fastest way out. For a company whose production line has stopped while customers chase deliveries, that pressure is real, and we will not pretend otherwise.

But why people pay and whether paying solves the problem are separate questions. Almost every reason above rests on one assumption: after payment the data comes back, the leak stops and the incident is over. The sections below test that assumption against public evidence.

Our own position is clear - we do not pay ransoms, negotiate on a client's behalf, or buy or transfer cryptocurrency - but the decision is yours. Our job is to make sure it rests on facts.

If we pay, will the data definitely come back?

Not necessarily, and the gap is wider than most people expect. The FBI puts it plainly: paying does not guarantee you will get any data back, and some victims who paid never received a decryption key.

Even with a decryptor in hand, problems are common:

  • The decryptor can be broken. In December 2019 Emsisoft disclosed that the updated decryptor Ryuk supplied to paying victims contained a calculation error: on partially encrypted files larger than 54.4 MB it cut off one byte too many at the end. VHD and VHDX virtual disks and database files such as Oracle's keep important information in exactly that position, and failed to load after decryption.
  • What comes back is incomplete. In Cybereason's 2024 survey only 47% of companies that paid got their data and services back uncorrupted.
  • Decryption takes time as well. The tool has to be run against every affected host and data set. Decrypting, verifying and bringing back dozens of hosts and terabytes of data is still work the organisation must organise, so downtime does not vanish because a payment was made.

The other promise is deletion of stolen data. In February 2024, after Operation Cronos led by the UK National Crime Agency took control of LockBit's infrastructure, the NCA stated that some of the data on LockBit's systems belonged to victims who had paid - evidence that payment does not guarantee deletion, whatever the criminals promised.

Then there is the idea that paying ends it. In the same Cybereason survey, 78% of companies that paid were held to ransom again, and 63% said they were asked to pay more the second time. Payment closes no entry point; it only proves the organisation will pay.

What the attacker promisesWhat public evidence shows
Pay and the decryptor arrivesFBI: payment does not guarantee data back, and some payers never got a key
The decryptor restores everythingRyuk's decryptor truncated large files; only 47% of payers recovered uncorrupted data
Stolen data is deleted after paymentThe NCA found paying victims' data on LockBit's systems
You will not hear from them again78% of paying companies were held to ransom again

What are the legal and compliance risks of paying?

What follows summarises published rules and official guidance. It is not legal advice; rely on the competent authorities and your own counsel.

In mainland China. On 6 February 2026 the People's Bank of China and seven other authorities issued the Notice on Further Preventing and Handling Risks Related to Virtual Currencies (Yinfa [2026] No. 42), which repealed the 2021 notice (Yinfa [2021] No. 237). It restates that virtual-currency business activities in China, including exchange between fiat and virtual currency, are illegal financial activities and strictly prohibited; that financial institutions, including non-bank payment institutions, must not provide account opening, fund transfer or clearing and settlement services for them; that civil acts by any organisation or individual investing in virtual currency contrary to public order and good morals are void; and that fraud, money laundering and other crimes involving virtual currency are to be pursued under the law.

The notice is not written about ransoms, but the practical meaning is clear. Turning yuan into bitcoin or USDT to pay a ransom can realistically only happen through prohibited exchange channels or overseas platforms, with no recourse if anything goes wrong. State-owned entities, listed companies and regulated sectors usually have their own rules on expenditure, disclosure and incident reporting, and workarounds such as an individual advancing the money for later reimbursement can create a bigger problem at audit. The Ministry of Public Security's cyber security bureau also lists not paying a ransom lightly among the three don'ts in its September 2026 advisory.

US nexus. The US Treasury's Office of Foreign Assets Control (OFAC), in its updated advisory of 21 September 2021, states that the US government strongly discourages paying ransoms. Payments to sanctioned persons or comprehensively embargoed jurisdictions can violate sanctions, and OFAC may impose civil penalties on a strict liability basis - a person can be liable without knowing the recipient was sanctioned. The advisory names financial institutions, cyber insurers and digital forensics and incident response firms that facilitate payments on behalf of victims as also at risk, and treats a self-initiated, timely and complete report to law enforcement, plus cooperation, as mitigating factors. OFAC has designated a number of ransomware-linked individuals and groups, and virtual currency exchanges that moved ransom proceeds, such as SUEX in September 2021.

UK nexus. The Office of Financial Sanctions Implementation's guidance on ransomware and financial sanctions (updated January 2026) states that the UK government does not condone paying ransoms; that making funds available to an asset-freeze target through a ransom is a breach of financial sanctions and a serious criminal offence that can carry a custodial sentence or a monetary penalty; and that ransomware payments are unlikely to be considered appropriate for an OFSI licence. Where victims report through the national cyber incident portal, voluntarily disclose to OFSI and cooperate with law enforcement, OFSI and the NCA are more likely to resolve a case without a monetary penalty or criminal investigation.

Foreign-invested companies in China, and any business with an overseas parent, US dollar settlement or a US-connected party, should bring legal and compliance in before any conversation about payment begins.

What are decryption brokers, and how do you spot one?

Some services market themselves as ransomware decryption or recovery without paying, but what they actually do is contact the attackers on the victim's behalf, pay the ransom, obtain the decryptor, and bill the victim for the ransom plus a fee.

This is documented, not speculation. In May 2019 the US non-profit newsroom ProPublica investigated two US data recovery firms that claimed to decrypt with their own technology. Proven Data Recovery's CEO acknowledged that paying attackers was standard procedure, and ProPublica traced four of its ransom payments to SamSam on the blockchain - wallets the US Treasury later placed under sanctions. The other firm, MonsterCloud, told visitors not to pay the ransom, yet quoted one client US$25,000 where the underlying ransom was about US$7,000. In China, the first of the three don'ts in the Ministry of Public Security's September 2026 advisory is not to trust online decryption tools or decryption agents, to avoid being defrauded twice.

A broker that pays on your behalf passes every risk in the previous sections straight through to you. The decryptor can still be broken, deletion is still unverifiable and the money still reaches the attackers - only at a higher price, and possibly without you knowing a ransom was paid at all. Useful tests:

What to ask or look atWhat genuine technical recovery looks likeWarning signs
Why recovery is possibleA clear path: a named public decryptor and the builds it covers, a known implementation flaw, repair of intermittently encrypted files, backups and snapshotsA proprietary algorithm or inside channel, or claims to crack the newest builds of families with no public tool
What they need from youThe ransom note and a few encrypted samples for identificationThe contact details, victim ID or negotiation page address from the note
How timing is setEstimated from data volume and repair difficultyDepends on when the other side replies
How the price is setA written quote based on assessed effortA price that moves with the ransom amount, or a percentage of it
How they get paidCorporate bank account with invoicesPersonal accounts or cryptocurrency only, or full payment or a deposit up front
What the contract saysScope, deliverables, acceptance criteria and what happens if recovery failsOnly verbal promises of 100% decryption or guaranteed recovery

How a test decryption is run matters. Attackers themselves offer to decrypt a few files for free, so a provider that decrypts a handful of your samples has only shown it can get the key - not that it did not pay for it. Stronger evidence: you choose the files, including large files and databases; the provider explains how the decryption works; and the contract states that no contact will be made with, and no payment made to, the attackers. A provider willing to sign that clause at least has confidence in its own technical route.

How else can data be recovered without paying?

Not paying does not mean giving up on the data. Recoverability varies with the family, version, encryption method and state of backups, and the usual paths are:

  • Public decryptors. For a small number of families, leaked keys, law enforcement seizures or implementation flaws have produced decryptors published by police agencies or security vendors. They usually work only for specific builds and must be matched before use.
  • Backups, snapshots and off-site copies. In Sophos's 2026 survey, 66% of organisations whose data was encrypted recovered through backups. Storage and hypervisor snapshots are often administered separately from the backup system and are frequently overlooked.
  • Database and virtual disk repair. Many families encrypt only the start of large files or encrypt intermittently, leaving most data pages and disk regions intact and readable business data extractable - see database encrypted by ransomware.
  • Remnants and downstream data. Remnants in unallocated space, copies on staff endpoints, and the same records in connected systems.

Which path works, and how far it gets you, can only be established by assessing read-only copies; the overall reasoning is in can encrypted files be recovered.

Recovery is half the job. The other half is finding the entry point, removing back doors and rotating every credential - otherwise you can be encrypted again whether or not you paid. See why ransomware keeps coming back and our incident response service.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related questions

Related solutions

FAQ

Follow-up questions

  • The attackers offer to decrypt a few files for free - does that mean everything will decrypt if we pay?

    No. Free test decryptions are usually limited in number and size and often exclude valuable files such as databases and backups, so all they prove is that the attackers hold the matching private key. Failures happen precisely outside that scope - in large files, databases and virtual disks. In the Ryuk case Emsisoft disclosed, the decryptor's bug only affected partially encrypted files over 54.4 MB, leaving VHD, VHDX and Oracle database files unloadable after decryption - exactly the kind of file a test never covers. Sending samples or uploading them to the attacker's page is also a form of contact that tells them you are considering payment.

  • Can the ransom be negotiated down?

    Negotiation is common: in Sophos's 2026 survey, 51% of organisations that paid ended up paying less than the initial demand. But negotiating means you are already in the payment process - contact, bargaining, payment, waiting for a decryptor - and none of the risks above shrink because the amount did. We do not negotiate on a client's behalf, and we advise against making contact just to test the price. That time is better spent inventorying backups and snapshots and establishing how much can be recovered without the attackers.

  • We have already paid. What now?

    Payment does not close the incident. These steps still matter:

    • Back up the encrypted data before running any decryptor. This was Emsisoft's advice after the Ryuk case: a faulty decryptor rewrites files directly, and without a copy there is no way back. Check the attacker's decryptor in an isolated environment first to make sure it carries nothing else.
    • Report it and keep the payment records. Transaction times, amounts, wallet addresses and chat and email records are all evidence; the FBI also urges victims to report whether or not they paid.
    • Find the entry point, remove back doors and rotate every credential. Paying patched nothing, and with the door open the next demand may come sooner.
    • Expect further demands. Do not give way to new requests such as paying again to have data deleted, and assess the data exposure separately.
  • Is it illegal for a company in China to pay a ransom in bitcoin or USDT?

    That is for legal counsel to judge on the facts, and we do not give legal advice. The public facts are these: Yinfa [2026] No. 42, issued in February 2026, restates that virtual-currency business in mainland China, including fiat-to-crypto exchange, is an illegal financial activity; that financial institutions and non-bank payment institutions must not provide account opening, fund transfer or clearing services for it; and that civil acts investing in virtual currency contrary to public order and good morals are void. The channels you would rely on to buy and move coins for a ransom therefore have no legal protection and offer no recourse, and the company's own approval, audit and disclosure obligations come into play as well. The Ministry of Public Security's advice is not to pay lightly and to report to the local police immediately. For a definitive view, consult the authorities and your counsel.

  • If the company decides to pay anyway, what can NoRansom still do?

    We take no part in anything connected to a transaction with the attackers: no contact, no negotiation, no buying or transferring cryptocurrency, and where a client transacts with an attacker independently the risks and consequences rest with the client. The technical work is still needed alongside that: preserving evidence and producing a forensic report, establishing the entry point and the extent of compromise, removing back doors and persistence, assessing which data can be recovered without the attackers, and hardening afterwards. The assessment also shows management how much data genuinely depends on the attackers.

Sources

External links are provided for reference only. The content is published by third parties and does not represent our position.

Updated