In IT, Innovation and Startups

David Stevenson

Zero tolerance: UK slams legal guillotine on ransom payments in sweeping cybercrime overhaul

Zero tolerance: UK slams legal guillotine on ransom payments in sweeping cybercrime overhaul

The government has announced a stringent regulatory package designed to cripple ransomware operations that have been paralysing hospitals, schools, and businesses across the country. Under the new rules, public sector entities—including the NHS, local councils, and educational institutions—will be prohibited from paying ransoms to cybercriminals. Private companies will retain the option to negotiate with hackers, but only after securing explicit government approval and reporting their intent to pay.

The Home Office estimates that ransomware attacks cost the UK economy hundreds of millions of pounds annually, with high-profile incidents such as the 2022 attack on Advanced, which disrupted NHS 111 services, exposing systemic vulnerabilities. The new legislation aims to disrupt the financial incentives driving these crimes, particularly given that a significant portion of ransomware gangs operate under the protection of sanctioned states like Russia and North Korea. Security Minister Dan Jarvis stated that the objective was to dismantle the ransomware business model by shifting from reactive defence to proactive disruption of cybercriminal networks.

A mandatory reporting system for major cyber incidents will also be introduced, ensuring that threat intelligence is rapidly shared with law enforcement. This database will enable agencies like the National Cyber Security Centre (NCSC) to identify attack patterns and coordinate pre-emptive strikes against ransomware infrastructure. The policy follows a 40% surge in ransomware cases reported to the NCSC in 2023, with healthcare and education sectors being prime targets due to their reliance on outdated IT systems.

Critics argue that while the ban on public sector payments may reduce short-term extortion revenue, it could also lead to more destructive attacks as criminals attempt to force compliance through data destruction. However, the government insists that the long-term strategy—combining stricter financial controls, enhanced cyber defences, and international cooperation—will degrade ransomware operations more effectively than negotiation. Private firms failing to seek approval before paying ransoms will face hefty fines, reinforcing the message that capitulation funds further criminality.

The move aligns with broader G7 efforts to target cryptocurrency laundering networks used by ransomware groups. With UK banks now freezing transactions linked to digital wallets associated with cybercrime, the hope is that cutting off financial flows will render these operations unsustainable. Whether the measures will stem the tide of attacks remains uncertain, but the government’s stance is clear: paying ransoms only fuels the crisis.