Ransomware Payment Debate

The cluster focuses on discussions about whether ransomware victims should pay demands, with most comments arguing against it due to incentives for criminals, risks of repeat attacks, and calls to criminalize payments.

📉 Falling 0.3x Security
2,898
Comments
18
Years Active
5
Top Authors
#1385
Topic ID

Activity Over Time

2008
3
2009
8
2010
7
2011
8
2012
17
2013
33
2014
39
2015
105
2016
130
2017
202
2018
71
2019
241
2020
443
2021
835
2022
149
2023
271
2024
198
2025
138

Keywords

e.g IT OP zdnet.com ATM techtarget.com FBI ycombinator.com QA wikipedia.org ransom ransomware pay paying criminal attackers payment criminals illegal attacks

Sample Comments

paulpauper Jan 31, 2024 View on HN

Good. paying ransoms only incentivizes the behavior.

jacquesm Nov 8, 2015 View on HN

That's naive. If you pay a ransom they'll be back shortly for more. You've just turned yourself into an ATM for your attackers.

nradov May 23, 2024 View on HN

Banning ransoms directly is a good idea. Even if that results in massive losses or even bankruptcies by victims, that is an acceptable consequence to prevent money from flowing to criminal organizations and hostile foreign governments. Sometimes you have to amputate a damaged limb to save the body. Paying a ransom in any circumstance should be a criminal offense.

raverbashing Jul 3, 2021 View on HN

Given that paying the ransom only outs yourself as a potential repeated target who pays, it was a wise decisionSource: https://searchsecurity.techtarget.com/news/252502519/Repeat-...

rolph Apr 26, 2023 View on HN

why am i reminded of ransomware? maybe because extortion means punishment, if you dont pay, but ransomware, means return to square one if you pay. i hope this kind of behavior gets the interaction required, to end it.

evan_ Sep 5, 2012 View on HN

paying the ransom is just as bad, since it confirms that there's something worth covering up.

jay_kyburz May 10, 2021 View on HN

Is it illegal to pay the ransom?

Lucasoato Sep 21, 2025 View on HN

It should be illegal to pay a ransom to cyber criminals, every time it happens you’re increasing the incentives for these activities and you’re making it more likely to happen again in the future. If it’s illegal, these groups would feel less attracted to attack companies, because they know they wouldn’t be compensated for it.

mashlol May 23, 2024 View on HN

I'm ignorant but I've never understood why people actually pay the ransom. Aren't the attackers anonymous? What stops them from asking for another $Y after they get their $X, and not actually removing the ransomware? There's not much incentive for the attackers to actually do what they say after you pay them, right?

datadata Jun 18, 2021 View on HN

Why not just criminalize paying ransoms? Remove incentives and don't fund criminals.