New UK law would ban ransomware payments by publicly funded orgs

The British government has announced plans to move forward with a law that would bar public organizations from paying off ransomware attackers. The proposed legislation would add schools, town councils, National Health Service (NHS) hospitals and critical infrastructure managers to a ban which already applies to the national government.

The logic behind banning payments is simple. If cybercriminals know a ransomware attack against a UK school or hospital won't get them paid, they'll look somewhere else for a more lucrative target. Security Minister Dan Jarvis said that the government is "determined to smash the cyber criminal business model," and added that laws in the proposed package will require even private businesses to seek guidance from the government before paying a ransom.

Since the WannaCry attack on the NHS in 2017 launched the modern era of ransomware attacks, the UK has suffered a number of serious incidents. In the last two years alone, attacks have hit the British Library, the BBC and the Ministry of Defence. This may explain why, according to the government's announcement, "nearly three quarters" of public comments on the ban legislation were supportive.

Although bans on ransom payments are a popular solution to the ever-increasing scourge of ransomware, there's currently not much data on whether they work. Two US states, North Carolina and Florida, have enacted similar bans, but it's hard to say what impact they've had. Critics argue that some organizations, especially hospitals, can't afford the long-term disruption of leaving the ransom unpaid, and may choose to pay in unaccountable ways. Furthermore, some hacking groups have aims other than money, and may continue ransomware attacks to sow political chaos.

The UK is moving into uncharted territory as the first nation to pass a ransomware payment ban. We'll be interested to see whether it helps get attacks under control. Either way, the outcome is likely to inform how other countries respond to the continuing threat of cybercrime.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/new-uk-law-would-ban-ransomware-payments-by-publicly-funded-orgs-210851334.html?src=rss https://www.engadget.com/cybersecurity/new-uk-law-would-ban-ransomware-payments-by-publicly-funded-orgs-210851334.html?src=rss
Vytvořeno 19h | 22. 7. 2025 22:40:23


Chcete-li přidat komentář, přihlaste se

Ostatní příspěvky v této skupině

T-Mobile's Starlink satellite service is now available after months of testing

T-Mobile's satellite-to-mobile service is now officially

23. 7. 2025 17:20:31 | Engadget
Google adds its photo-to-video tech to YouTube Shorts

Google has been putting more AI tools in just about all of its services, and two more are getting the treatment. First up, Google Photos is

23. 7. 2025 17:20:29 | Engadget
Anker Nebula X1 projector review: The king of outdoor movies, if you can afford it

My dream projector delivers the brightest and sharpest image. But it also has to be easy to move around and set up anywhere — especially outdoors. Anker’s

23. 7. 2025 17:20:28 | Engadget
Uber will help pair women riders and drivers in the US

Uber has announced that Women Preferences, a feature which will allow women riders to be matched e

23. 7. 2025 17:20:27 | Engadget
Trump's AI Action Plan targets state regulation and 'ideological bias'

At the start of the year, President Trump announced his

23. 7. 2025 17:20:26 | Engadget
Sonos gets to keeps its CEO, as a treat

Sonos’ Very Bad 2024 is well documented. Its redesigned app e

23. 7. 2025 17:20:25 | Engadget
A year later, the Sonos Ace is finally fulfilling its potential

2024 was an awful year for Sonos. Its

23. 7. 2025 17:20:24 | Engadget