UK companies and organisations are to be banned from making ransom payments when they have been hacked, the government has announced.
It is part of a crackdown on criminal hacking groups following a surge in ransomware attacks on businesses and organisations.
“The UK government does not encourage or condone ransomware payments,” in an update to its ransomware guidance.
In a separate statement today, the government revealed it had sanctioned six Russian nationals involved in the development or deployment of ransomware in the UK and US.
“Making or facilitating a ransomware payment risks exposing those involved to civil or criminal penalties,” the ransomware guidance stated.
“We’re targeting cyber criminals who have been involved in some of the most prolific and damaging forms of ransomware,” security minister Tom Tugendhat said.
The government identified ransomware groups including Conti and Ryuk, which are responsible for cyber attacks on 149 businesses and individuals.
They are believed to have extracted £27mln worth in ransoms, with Conti extracting £10mln from 104 UK victims.
Conti was involved in multiple attacks on schools, companies and local authorities before disbanding in May 2022- though experts believe members of the group are still involved in attacks.
In 2021 the group extorted US$180mln globally, research from Chainanalysis found.
“Ransomware criminals have hit hospitals and schools, hurt many and disrupted lives, at great expense to the taxpayer,” Tugendhat added.
The national crime agency (NCA) has begun a “complex, large-scale” investigation in order to disrupt the threat of ransomware actors, with the current sanctions just one of the steps.
Graeme Biggar, director general for the NCA, said: “The sanctions are the first of their kind for the UK and signal the continuing campaign targeting those responsible.
“Criminals and those that support them are not immune to UK action, and this is just one tool we will use to crack down on this threat.”