Abdolmadjid Masoomi

Should You Pay a Ransomware Demand? The Case Against Certainty

Payment buys a promise from a counterparty with no reason to keep it.

Signed
Abdolmadjid Masoomi
Published
2026-09-14
Length
8 min read · 1,712 words
Status
opinion

The question of should you pay ransomware is not an ethical dilemma but an epistemic failure. Organisations cannot verify the promises made by attackers, making payment a high-risk gamble against a counterparty with no incentive to honour it. Decisions made under duress lack the evidence required for sound judgement.

The decision of whether to pay a ransomware group is rarely a simple choice between ethics and survival. It is often framed as a moral failing to pay criminals, or a pragmatic necessity to save the business. This framing obscures the core problem. The stronger argument is epistemic: every benefit of paying is an unverifiable claim by the attacker.

When an organisation faces encryption, the attackers offer a specific set of outcomes. They promise a working decryptor. They promise to delete the stolen data. They promise not to return. These are commercial terms in a transaction with a counterparty that has no reputation to protect and no legal obligation to perform.

Payment buys a promise from a counterparty with no reason to keep it. The rational response is not to weigh morality against survival, but to recognise that the transaction is fundamentally asymmetric. The attacker holds all the information and all the leverage. The victim holds the money and none of the certainty.

What payment is supposed to buy

The ransomware negotiation is a transaction for three specific deliverables. The first is the decryption keys to restore encrypted files. The second is the assurance that exfiltrated data will be destroyed. The third is the guarantee that the attackers will not target the organisation again. Each of these deliverables requires verification that is structurally impossible during the crisis.

Verifying the decryption keys requires testing them against a sample of files. Attackers typically decrypt a handful of the victim’s own files, often small and non-critical ones, to prove the keys work. This sample is not representative of the entire dataset. The keys may fail on other files due to corruption, different encryption parameters, or simple incompetence. Testing the full dataset before payment is impossible because the files are encrypted.

Verifying data deletion requires independent confirmation. Attackers may provide screenshots or logs of deletion. These are easily fabricated. There is no third-party auditor for the dark web. The organisation must trust the word of criminals who have already demonstrated a willingness to lie.

The guarantee against repeat attacks is the most fragile promise. Criminal groups operate on volume. They sell access to other actors. They may sell the same victim list to competitors. There is no contract to enforce this promise. The only thing that prevents a repeat attack is the attacker’s discretion, which is not a reliable security control.

Decryptors that fail

The primary reason organisations pay is to regain access to their data. The decryptor is the product being sold. Yet the market for ransomware decryptors is rife with failure. Many groups release tools that are buggy, incomplete, or incompatible with specific file types.

Most ransomware relies on standard, well-documented cryptographic algorithms, meaning recovery hinges on the attacker’s secret key rather than an obscure method. While backups or specialised tools from security researchers may offer a path to restoration, a flawed decryptor poses a severe risk. If such a tool is used incorrectly, the data is not necessarily lost forever, but corruption can occur. This danger is particularly acute when encryption is applied to database files or complex application structures, where even minor errors in the decryption process can render entire databases unusable.

There are also cases where the decryptor works for some files but not others. This partial success creates a false sense of security. The organisation may believe the crisis is over, only to discover critical data remains locked. The cost of this partial failure is often higher than the initial ransom, as it requires manual reconstruction of data.

The technical complexity of modern ransomware means that even well-funded groups make mistakes. They may rush the deployment of their tooling. They may fail to test against all operating systems or file formats. The victim organisation has no way to know the quality of the tool until after payment is made. This is a purchase with no return policy.

Deleted data you cannot verify

Data exfiltration is the second lever of pressure. Attackers steal data before encrypting it. They threaten to publish this data if the ransom is not paid. Payment is supposed to trigger the deletion of this data.

The verification of deletion is non-existent. Attackers may provide a video of files being deleted. They may provide server logs. These are trivial to forge. There is no cryptographic proof that all copies of the data have been destroyed. The attackers may have already sold the data to other parties. They may have shared it with affiliates.

The concept of "deletion" in a distributed criminal ecosystem is meaningless. Once data is exfiltrated, it exists in multiple locations. The original attackers may delete their copy, but others may retain it. The organisation has no visibility into the broader criminal network.

This uncertainty creates a persistent risk. Even after payment, the organisation must assume the data is still in circulation. This leads to ongoing costs for monitoring, legal advice, and customer notification. The payment does not end the incident; it merely changes the nature of the response. The organisation is left with the burden of managing a breach that it paid to prevent.

Beyond the technical risks, there are significant legal and regulatory constraints. Many jurisdictions have laws that prohibit payments to sanctioned entities. These laws vary by country and change frequently. An organisation may inadvertently violate sanctions by paying a ransom.

Data protection law imposes strict obligations on organisations. While it does not explicitly ban ransom payments, it requires entities to demonstrate that they have taken appropriate security measures to protect data. A payment that fails to secure the data may be seen as a failure of due diligence, and crucially, such a payment does not remove the duty to notify the breach or the fact that the breach has occurred.

Regulators are increasingly scrutinising ransom payments. The legal landscape is complex and evolving. Organisations must navigate these constraints carefully.

The risk of legal action from third parties is also present. Customers, partners, and shareholders may sue the organisation for paying criminals. They may argue that the payment funded further criminal activity. The legal exposure is significant and difficult to quantify.

Deciding before the incident

The decision to pay should not be made in the heat of the moment. It should be part of a pre-defined incident response plan. This plan should outline the criteria for payment and the legal constraints that apply.

Organisations should consult with legal counsel before any payment is considered. The counsel should assess the sanctions risk and the regulatory implications. They should also evaluate the likelihood of recovering the data without payment.

The incident response team should include representatives from IT, legal, communications, and executive leadership. This team should have a clear mandate to evaluate the offer. They should not be pressured by emotional appeals or time limits.

The plan should also define the evidence required to justify payment. This might include independent verification of the decryptor, legal opinions on sanctions, and a cost-benefit analysis of recovery options. The decision must be based on facts, not fear.

What to prepare so the question never arises

The best way to avoid the ransomware dilemma is to reduce the impact of an attack. This requires robust backup strategies. Backups should be immutable and isolated from the network. They should be tested regularly to ensure they can be restored.

organisations should also invest in detection and response capabilities. Early detection can limit the scope of an attack. It can prevent data exfiltration and reduce the time to recovery. This reduces the leverage of the attackers.

Insurance can provide financial support, but it does not solve the technical problem. The insurance policy should be reviewed carefully to ensure it covers ransom payments and the associated legal costs. However, insurance should not replace good security practices.

The goal is to make the organisation a difficult target. This involves reducing the attack surface, improving visibility, and ensuring resilience. When the impact of an attack is manageable, the pressure to pay diminishes. The organisation can focus on recovery rather than negotiation.

For those interested in understanding the aftermath of such incidents, reading breach notifications can provide insight into the disclosure process. Understanding the breach consequences and leaks is also essential for preparing a response. Finally, recognising that decisions with lasting records are made under pressure highlights the importance of pre-planning.

Questions people ask

Should companies pay ransomware demands?

Paying ransomware demands is generally not recommended because the benefits are unverifiable. Attackers may fail to provide working decryptors or delete stolen data. The decision should be based on a pre-defined plan that considers legal constraints and recovery options, rather than immediate pressure.

Is it illegal to pay a ransom?

The legality of paying a ransom depends on the jurisdiction and the specific entities involved. Payments to sanctioned organisations are illegal in many countries, including those under EU regulations. Organisations must consult legal counsel to assess the risks before making any payment.

Do hackers delete data after ransom is paid?

There is no guarantee that hackers will delete data after payment. They may provide false evidence of deletion, or the data may have already been distributed to other parties. The organisation must assume the data remains in circulation and prepare for ongoing management of the breach.

Close

The ransomware negotiation is a trap for the unprepared. It exploits the urgency of the moment to bypass rational decision-making. The attacker offers certainty where none exists. They promise outcomes that they cannot control and cannot verify.

Organisations must reject this false certainty. They must recognise that payment is a high-risk transaction with a counterparty that has no incentive to perform. The rational choice is to rely on pre-defined plans, robust backups, and legal advice.

The question of whether to pay should not be a question at all. It should be a decision made in advance, based on evidence and constraints. When the incident occurs, the organisation should execute the plan. It should not negotiate with the enemy.

This approach minimises the impact of the attack. It protects the organisation from legal and financial risks. It ensures that the response is measured, not reactive. In the end, resilience is the only reliable defence against extortion.