Law and Governmentransom
Summary (tl;dr)
The term "ransom" is trending in the Law and Government sector due to a global surge in sophisticated ransomware attacks, particularly targeting government entities, coupled with evolving legislative efforts to ban or combat these payments, and recent high-profile incidents.
Essential Background
Ransomware has become an increasingly prevalent form of cybercrime where malicious actors encrypt an organization's data and demand payment, or "ransom," typically in cryptocurrency, for its release. The threat landscape has grown significantly, with the number of confirmed ransomware victims jumping dramatically in recent years, reaching over 7,500 publicly disclosed victims between April 2025 and March 2026, a 24.9% increase year-over-year. Historically, while the U.S. federal government has strongly discouraged paying ransoms, it has not outright prohibited companies from doing so, even if the payment involves a sanctioned entity.
The Full Story
"Ransom" is currently trending as governments worldwide grapple with a dramatic increase in ransomware attacks, often amplified by the use of AI hacking tools, which allow attackers to target multiple organizations simultaneously and automate various stages of an attack. In the first half of 2026 alone, government entities experienced 187 ransomware attacks globally, with the U.S. accounting for the largest share. High-profile incidents include the Anchorage Police Department being forced offline in January 2026 due to a third-party cyberattack, and Foster City, California, pausing public services in March 2026 following a ransomware breach.
In response to this escalating threat, discussions and legislative actions around banning ransomware payments are gaining momentum. The United Kingdom is planning a ban on ransomware payouts from public sector organizations and critical national infrastructure groups. Similarly, New York has proposed legislation that would apply to non-government entities as well, with penalties for non-compliance. On the federal level, U.S. President Donald Trump recently signed a National Security Presidential Memorandum (NSPM) in August 2026, empowering federal law enforcement to utilize cyber tools and private sector expertise to disrupt transnational criminal organizations responsible for ransomware and other cybercrimes targeting Americans.
Why It Matters
The trend signifies a critical juncture in the fight against cybercrime, highlighting the severe operational and financial costs of ransomware attacks on essential services and critical infrastructure. Governments are increasingly recognizing the need for more assertive strategies beyond just discouraging payments, as evidenced by proposed bans and new federal initiatives. However, the effectiveness of payment bans remains a subject of debate within cybersecurity circles, with some arguing they may only shift hacker tactics rather than eliminate the threat. The integration of AI into ransomware attacks also means that organizations, especially in the public sector, face a more sophisticated and rapid threat environment, making robust cybersecurity measures and international cooperation more vital than ever.
Geographic Location
- United Kingdom (planning a ban on ransomware payouts from public sector organizations and critical national infrastructure groups)
- New York, United States (proposed state legislation to prohibit ransomware payments)
- Anchorage, Alaska, United States (Police Department servers taken offline due to a cyberattack)
- Foster City, San Mateo County, California, United States (city services paused due to a ransomware attack)
- Washington, D.C., District of Columbia, United States (White House signed a National Security Presidential Memorandum to combat cybercrime and ransomware)
- Germany (increased ransomware activity against government organizations)
- South Africa (increased ransomware activity against government organizations)