By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Daily LondonDaily London
Font ResizerAa
  • UK & Europe News
  • World Affairs
  • Tech & Innovation
  • Culture & Society
  • Voices of London
Reading: Why you should never pay a ransomware scammer
Share
Font ResizerAa
Daily LondonDaily London
  • UK & Europe News
  • World Affairs
  • Tech & Innovation
  • Culture & Society
  • Voices of London
Search
  • UK & Europe News
  • World Affairs
  • Tech & Innovation
  • Culture & Society
  • Voices of London
Follow US
© 2025 Daily london. All Rights Reserved.
Daily London > World Affairs > Why you should never pay a ransomware scammer
World Affairs

Why you should never pay a ransomware scammer

Daily London
By Daily London
Published: November 17, 2025
Share

Daily London

While cyber attacks on huge telcos, airlines and superannuation funds grab the headlines, small and medium-sized business owners are increasingly being seen as easy targets.
In an alarming new study of the Australians whose devices have been slowed or seized by hackers, experts warned paying up to protect business reputations could be throwing away money for nothing and even earning a place on “sucker lists” for repeated targeting.

The report based on the 2023 Australian Cybercrime Survey found nearly 5 per cent of respondents had received a ransom message on their device in the previous year, well up on the 2.1 per cent just two years earlier.

While cyber attacks on huge telcos, airlines and superannuation funds grab the headlines, small and medium-sized business owners are increasingly being seen as easy targets. (Getty Images/iStockphoto)

What’s more, many were targeted multiple times, particularly if they chose to cave in to the ransomware criminals’ demands.

“SME [small to medium enterprise] owners were more likely to have received multiple messages and to have previously paid a ransom. 

“Strong messaging should dissuade SME owners from making these payments, which increase the chances of repeat victimisation.”

While some scammers use ransomware – malicious software that encrypts or blocks access to files until a user has paid a ransom – to go “big game hunting” for large companies, the authors noted the majority went after SMEs.

Those in the multibillion-dollar global industry considered them “lucrative targets” due to generally having less sophisticated cybersecurity but enough revenue, data and access to other potential victims to be worthwhile.

Voce and Morgan found that among the 331 victims studied, the amount of money demanded was often relatively small, a mean of about $12,000 for business owners and $7000 for others. The median figure was much lower, less than $500 for almost 60 per cent of victims.

The researchers stressed how important it was to push out stronger messaging of the government’s advice to never pay a ransom (A Current Affair)

But the researchers stressed how important it was to push out stronger messaging of the government’s advice to never pay a ransom, particularly in light of the “sucker lists” cybercriminals reportedly share among themselves featuring individuals and organisations who have made previous payments.

“Importantly, over 40 per cent of SME owners had paid in response to one of these previous ransom messages, a significantly higher proportion than among other victims,” the report found.

“SME owners were also more likely to have paid following the most recent ransomware incident. 

“This fuels the ransomware business model and can make SME owners appear to be easy to scare and manipulate, increasing their chances of repeat victimisation.”

Business owners (22.6 per cent) were much more likely to have paid the ransom than non-owners (7.6 per cent) but the researchers warned payment was no “guarantee that files and systems will be restored and data will not be sold or shared”.

Scarily, a quarter of ransomware reports to the Australian Cyber Security Centre involved “double extortion”, where victims were also pushed for money to stop their information leaking. 

The report called for better education about how to spot and avoid suspicious links, respond to third-party data breaches and manage personal devices or working from home, as well as help to help victims remove the malware.

But they warned that was not enough, saying “there must also be technological solutions that can help protect business owners”.

You Might Also Like

Six-year-old girl is the sole survivor of a family that perished in crash
Enormous bruise spotted on Donald Trump’s hand
NSW Health issues measles warning after positive case took Qantas flight from Adelaide-Sydney
Canadian teenager found dead identified as Piper James
Gang jumps fence, smashes door to steal two BMWs in violent home invasion
Share This Article
Facebook Twitter Whatsapp Whatsapp Email Print
Previous Article Bangladesh tribunal sentences ousted leader for crimes against humanity
Next Article Cyclone risk raised to ‘high’, residents urged to prepare

Stay Connected

16k Like
85k Follow
45.6k Subscribe
Telegram Follow
- Advertisement -

Latest News

Interstate crews brought in to help firefighters battle massive blaze
World Affairs
International Olympic Committee grills organisers at Milan meeting
World Affairs
Search for vulnerable woman who disappeared from bus stop nearly two months ago
World Affairs
Man arrested after allegedly mimicking shooting near footbridge
World Affairs

Daily London – The Global Pulse from the UK

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[email-subscribers-form id=”1″]

Daily LondonDaily London
© 2025 Daily London. All Rights Reserved.