UK to ban making ransomware payments for some organizations — targets 'public sector bodies and operators of critical national infrastructure'

ransomware
(Image credit: Getty / da-kuk)

Ransomware gangs might have to scratch a few targets off their lists. The UK High Office and National Cyber Security Centre (NCSC) announced proposals to ban ransom payments in an effort to "crack down on cyber criminals and safeguard the public."

According to the announcement, the proposals would prohibit "public sector bodies and operators of critical national infrastructure, including the [National Health Service], local councils and schools," from making ransomware-related payments. They would also require other businesses planning to pay a ransom to notify the UK government so it can "provide those businesses with advice and support" before the payment is made. (Including a heads-up if such a payment would violate sanctions on Russia.)

The proposals wouldn't require companies to inform the UK government of a ransomware attack if they didn't plan to pay the ransom. But the announcement indicated that a mandatory reporting policy is in the works, too, in a bid to "equip law enforcement with essential intelligence to hunt down perpetrators and disrupt their activities" and "better protect British organisations and industry." That should make it more difficult to deploy ransomware in the UK without risking law enforcement's ire.

"The new package of measures will lead the way in tackling ransomware and are designed to strike against cyber criminals’ business model, bolstering our national security and protecting key services and businesses from disruption - delivering on our Plan for Change," the Home Office and NCSC said in the announcement. "They follow an extensive consultation with stakeholders across the UK, which showed strong public backing for tougher action to tackle ransomware and protect vital services."

The UK and Singapore previously said in January 2024 that they "strongly discourage anyone from paying a ransomware demand" because doing so:

  • Does not guarantee the end of an incident, or the removal of malicious software from your systems
  • Provides incentives for criminals to continue and expand their activities
  • Provides funds that criminal actors can use for illicit activity
  • Does not guarantee you will get your data back

Now the UK is looking to outright ban those payments rather than merely "strongly discouraging" them. The news follows reports earlier this week that a 158-year-old UK company was forced to shut down following a ransomware attack, at the cost of 700 jobs.

"Cyber criminals have not only cost the nation billions of pounds but in some cases have brought essential services to a standstill," the Home Office and NCSC said. "The devastating consequences are not just financial but can put lives in danger, with an NHS organisation recently identifying a ransomware attack as one of the factors that contributed to a patient’s death. These attacks have brutally exposed the alarming vulnerability at the core of our public and private institutions, from flagship British retailers and essential supermarkets including the Co-op to NHS hospitals."

Follow Tom's Hardware on Google News to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button.

Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • -Fran-
    At a high level, this makes sense, even if it's hard to implement.

    My simplistic take is equivalent to funding the Police and forced entry + robbery investigation (prevention is regulation and such). If Companies need to start writing off "randsomware" as losses, they pay less taxes and it's really hard to prove whether they're weasling out or not, so the Gov's need to grow their "internet policing" when facing Corporations in order to actually not lose in the long run.

    On the flipside... More "internet policing"... Ugh...

    Regards.
    Reply
  • DS426
    -Fran- said:
    At a high level, this makes sense, even if it's hard to implement.

    My simplistic take is equivalent to funding the Police and forced entry + robbery investigation (prevention is regulation and such). If Companies need to start writing off "randsomware" as losses, they pay less taxes and it's really hard to prove whether they're weasling out or not, so the Gov's need to grow their "internet policing" when facing Corporations in order to actually not lose in the long run.

    On the flipside... More "internet policing"... Ugh...

    Regards.
    Fortunately, this mainly impacts the remaining public sector entities like schools and public hospitals. Private sector businesses will probably get the "we don't recommend paying it" spiel but still have the option assuming it doesn't violate Russian sanctions. Still, one worry is that some orgs just won't report an incident (or report it as ransomware, anyways) and pay a ransom behind the scenes. I don't think this would be common, and overall, this measure does make the U.K. look like a less attractive target for ransomware gangs.

    Also recall and for those that don't know that OFAC in the U.S. warned about potential penalties for U.S. companies that violate sanctions via ransomware payments (and note this was prior to Russia's invasion into the Ukraine):
    https://ofac.treasury.gov/recent-actions/20201001
    Reply
  • hotaru251
    -Fran- said:
    On the flipside... More "internet policing"... Ugh...
    i mean that part of world has been pushing that more underr guise of "security" for past few yrs.

    its meant to be in good faith but theres ofc issues w/ it but its only something they'll learn properly after it happens.

    Honestly if everyone refused to pay they'd eventually stop doing it as there would be no profit.
    Reply
  • Notton
    This sort of policy would be sensible only if the government can increase funds to beef up cyber security and provide an unlocking service for those affected.

    Otherwise it's no better than police when your TV/bike/car/etc. gets stolen. You won't be compensated for your loss (meaning you have to pay for it out of your own pocket) and they'll never find it within a meaningful time.
    Reply
  • Alex/AT
    As fun as it is, total cryptocurrency ban would close the criminal ransom/laundering channel.
    Reply