Paying ransomware is a last resort, not the default response.
A ransomware attack can create 2 problems: unavailable systems and possible data theft. The FBI, CISA and other U.S. government agencies discourage ransom payments because payment does not guarantee restored access, deletion of stolen data or protection from another attack. Payment can also fund criminal operations and create sanctions-related legal risk.
If an attack is happening now, isolate affected systems, preserve evidence, contact an incident-response specialist and report the attack before deciding whether to pay.
The Ransomware Payment Decision at a Glance
| Situation | Recommended response |
|---|---|
| You have a verified, clean backup | Do not pay. Contain the attack and restore from backup. |
| Files are encrypted, but the attacker has not shown evidence of data theft | Investigate backups, decryptors and other recovery options before considering payment. |
| The attacker threatens to publish stolen data | Treat the incident as a possible data breach. Payment may not prevent publication. |
| You have no usable backup and essential operations have stopped | Get legal, technical, insurance and law-enforcement advice. Consider payment only after other options have been assessed. |
| The attacker may be sanctioned or linked to a sanctioned jurisdiction | Do not pay until sanctions counsel has reviewed the transaction. |
| A personal computer is infected | Disconnect it, preserve the ransom note and get professional help. Do not wipe it immediately if the files may be needed for investigation or decryption. |
Why Paying Ransomware Usually Fails
Payment Does Not Guarantee Data Recovery
Ransomware criminals may fail to provide a working decryption key, provide an incomplete tool or demand more money. The FBI has also warned that some victims are targeted again after paying.
Even a working decryptor may not restore every file. Files may be corrupted, backups may be damaged and the attacker may have changed systems before encryption began.
Payment Does Not Guarantee Stolen Data Will Be Deleted
Many ransomware attacks use double extortion. Attackers steal data before encrypting systems, then threaten to publish or sell it. Payment may restore some access, but it does not provide a reliable way to confirm that every copy of the stolen data has been deleted.
Organizations should therefore investigate whether personal, financial, health or confidential business information was accessed, whether or not they pay.
Payment Can Encourage Further Attacks
The FBI and CISA state that ransom payments encourage criminal actors, support further ransomware operations and may fund other illegal activity. Payment can also show that an organization is willing and able to pay, which may make it a more attractive target later.
Payment Does Not Remove the Attacker From the Network
A ransom payment addresses the demand. It does not fix the compromise.
Attackers may still have stolen credentials, persistence mechanisms or access to cloud accounts. Even after receiving a decryption key, an organization may need to rebuild systems, reset credentials, remove malware and investigate how the attacker got in.
What Should You Do Instead of Paying Ransomware?
1. Isolate Affected Systems
Disconnect infected computers and servers from the network. If several systems are affected, take the relevant network segment offline if necessary. This can limit the spread of ransomware to shared drives, servers and connected backups. CISA recommends isolating impacted systems early in the response.
Do not reconnect systems just to test whether the problem has stopped.
2. Preserve Evidence
Keep the ransom note, attacker communications, affected devices, relevant logs and a sample of encrypted files. Do not destroy evidence before an incident-response professional or law-enforcement agency has reviewed it.
The evidence may help identify the ransomware variant, determine whether data was stolen and establish whether a free decryptor is available.
3. Check Clean Backups and Available Decryptors
Use backups that were offline, immutable or otherwise protected from modification. CISA warns that ransomware can search for and encrypt accessible backups, so check a backup for malware before restoring it.
The No More Ransom project provides ransomware identification resources and decryptors for some variants. A decryptor will not be available for every strain, but checking is safer than assuming payment is the only recovery option.
4. Contact the Right Advisers
Organizations should involve:
- A qualified incident-response firm
- Internal or external legal counsel
- Their cyber insurer, if applicable
- Law enforcement
- Relevant regulators or sector authorities
The FBI asks victims to contact a local field office or report the incident to the Internet Crime Complaint Center. CISA also accepts ransomware reports and provides response guidance.
5. Assess Data Theft Separately From Encryption
A ransomware incident may involve unavailable systems and unauthorized access to data. Investigators should determine:
- Which systems were accessed
- Whether files were exfiltrated
- What information was involved
- Whether credentials were stolen
- Whether customers, employees or partners must be notified
- Whether contractual, regulatory or insurance reporting deadlines apply
Paying the ransom does not remove these duties.
When Might an Organization Consider Paying?
Payment may be considered only after a documented assessment shows that:
- No reliable backup or free decryptor can restore the necessary data.
- Rebuilding systems would create a serious and immediate threat to life, safety or essential services.
- The organization has assessed the cost, timing and feasibility of recovery without payment.
- Legal counsel has reviewed sanctions, regulatory and reporting risks.
- Law enforcement and the cyber insurer have been consulted where appropriate.
- Senior leadership has approved the decision and documented its reasons.
This is not a recommendation to pay. Organizations facing prolonged outages, patient-safety risks or disruption to essential services may need to assess every lawful recovery option. U.S. government guidance still discourages payment and warns that payment does not guarantee recovery.
Is Paying Ransomware Illegal in the United States?
Do not assume that paying ransomware is automatically lawful because an organization is under attack. The U.S. Department of the Treasury's Office of Foreign Assets Control warns that a payment may create sanctions risk if the ransomware actor, cryptocurrency wallet, intermediary or related jurisdiction has a sanctions connection. OFAC encourages victims to report attacks and consider sanctions compliance before arranging a payment.
A lawyer with sanctions and cyber-incident experience should review any proposed payment. The emergency nature of the attack does not remove the need for compliance analysis.
Does Paying Ransomware Remove Breach-Notification Duties?
No. Payment does not automatically eliminate breach-notification, privacy or regulatory obligations.
The U.S. Department of Health and Human Services states that ransomware affecting electronic protected health information can constitute a HIPAA security incident and may create a reportable breach, depending on the facts. Healthcare organizations must assess whether protected health information was compromised even if they pay and receive a decryption key.
Other industries may have separate state, federal, contractual or sector-specific reporting requirements.
Bottom Line
Do not pay ransomware unless qualified incident-response, legal and executive teams have assessed practical recovery options and determined that payment is a lawful last resort.
The safer default is to isolate systems, preserve evidence, investigate data theft, check clean backups and decryptors, report the attack and rebuild from trusted systems. Payment may appear faster, but it does not guarantee recovery, confidentiality or protection from another attack.