AI News AI资讯 16h ago Updated 11h ago 更新于 11小时前 46

Pay up or not? Ransomware surge has victims facing tough choices. 付钱还是不付?勒索软件激增使受害者面临艰难选择。

Ransomware victim numbers surged 389% in 2025, driven by malicious AI tools that lower attack costs and increase scalability. Jurisdictions like the UK are moving to ban ransom payments from critical infrastructure, though enforcement efficacy remains debated. Experts argue that prevention through exposure management and strict access controls is more effective than post-attack payment decisions. The shift away from payments may disrupt cyber insurance markets and push attackers toward less regu 2025年勒索软件攻击受害者数量激增389%,恶意AI工具(如WormGPT)降低了攻击门槛并提高了效率。 全球多地(如英国)正推动禁止公共部门和关键基础设施支付赎金,但实际威慑效果存疑且可能引发犯罪转移。 支付赎金不仅无法保证数据恢复,还会助长犯罪生态;专家呼吁通过暴露面管理和强化访问控制来降低攻击成功率。 单纯禁止支付可能导致网络安全保险市场动荡及保费飙升,建议政府通过补贴备份基础设施等激励措施替代禁令。

65
Hot 热度
70
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Ransomware victim numbers surged 389% in 2025, driven by malicious AI tools that lower attack costs and increase scalability.
  • Jurisdictions like the UK are moving to ban ransom payments from critical infrastructure, though enforcement efficacy remains debated.
  • Experts argue that prevention through exposure management and strict access controls is more effective than post-attack payment decisions.
  • The shift away from payments may disrupt cyber insurance markets and push attackers toward less regulated private sectors.

Why It Matters

This trend highlights the urgent need for AI practitioners and security engineers to integrate robust access controls and continuous monitoring into system architectures, as traditional perimeter defenses are increasingly bypassed by AI-augmented threats. For organizational leaders, understanding the strategic implications of payment bans and insurance shifts is critical for risk management and business continuity planning.

Technical Details

  • AI-Driven Attack Scaling: Malicious AI tools (e.g., WormGPT, FraudGPT) have reduced the cost per attack, allowing individuals to target multiple organizations simultaneously, leading to a 389% year-over-year increase in victims.
  • Regulatory Bans: The UK government is advancing legislation to prohibit ransom payments from public sector bodies and critical national infrastructure, aiming to dismantle the hacker ecosystem.
  • Prevention Strategies: Emphasis is placed on "exposure management," including enforcing multi-factor authentication, limiting internal system visibility, and implementing just-in-time access permissions to shrink the blast radius.
  • Market Shifts: Cyber insurance models are expected to adapt by excluding ransom payouts, potentially driving up premiums and forcing a pivot in how organizations budget for security resilience versus recovery.

Industry Insight

Organizations must prioritize proactive security hygiene and technical controls over reactive negotiation strategies, as the effectiveness of ransom payments is diminishing due to legal risks and lack of guaranteed data recovery. Stakeholders should anticipate increased pressure on the cyber insurance market and consider government-supported incentives for backup infrastructure to mitigate the financial impact of potential attacks.

TL;DR

  • 2025年勒索软件攻击受害者数量激增389%,恶意AI工具(如WormGPT)降低了攻击门槛并提高了效率。
  • 全球多地(如英国)正推动禁止公共部门和关键基础设施支付赎金,但实际威慑效果存疑且可能引发犯罪转移。
  • 支付赎金不仅无法保证数据恢复,还会助长犯罪生态;专家呼吁通过暴露面管理和强化访问控制来降低攻击成功率。
  • 单纯禁止支付可能导致网络安全保险市场动荡及保费飙升,建议政府通过补贴备份基础设施等激励措施替代禁令。

为什么值得看

本文揭示了AI如何彻底改变勒索软件的运作模式,使其从国家行为体专属变为低成本、高频率的犯罪商品,这对所有企业的网络安全策略构成直接威胁。同时,文章深入探讨了“禁止支付”政策的两难困境,为决策者在合规、业务连续性和风险管理之间提供重要的战略参考。

技术解析

  • AI赋能的攻击自动化:恶意AI工具(WormGPT, FraudGPT, BruteForceAI)使得黑客能以极低的成本同时针对多个目标,将过去需要大量资源才能完成的攻击简化为标准化操作,导致攻击成本大幅下降而防御成本上升。
  • 攻击规模与频率激增:数据显示,2025年全球确认的勒索软件受害者从2024年的约1,600家激增至7,831家,增幅达389%。黑客现在能在以往单次攻击的时间内同时瞄准四家机构。
  • 防御技术重点转移:专家强调“暴露面管理”(Exposure Management),包括持续监控设备、强制多因素认证(MFA)以及实施最小权限原则(如即时临时访问权限),以限制攻击者进入内部系统后的影响范围(Blast Radius)。
  • 数据恢复与支付博弈:尽管有专业数据恢复服务存在,但支付赎金并不保证数据删除或恢复,反而常导致二次勒索。关键基础设施(如水务、电力)面临两难:若无法恢复数据且禁止支付,后果可能比支付更严重。

行业启示

  • 从“事后支付”转向“事前预防”:企业应停止依赖支付赎金作为最后手段,转而投资基础安全卫生(Technical Hygiene),特别是加强身份验证和访问控制,因为大多数攻击仍利用已知漏洞和暴露的系统。
  • 政策制定需权衡副作用:虽然禁止支付赎金旨在切断犯罪资金链,但可能迫使犯罪分子转向监管较少的私营部门,并导致网络安全保险市场因风险重估而保费暴涨。政策应更具针对性而非“一刀切”。
  • 构建弹性而非仅靠禁令:政府和行业应通过税收优惠或直接补贴支持企业建立冗余备份系统和灾难恢复能力,从根本上降低勒索软件的可获利性,这比单纯禁止支付更能有效减少潜在损害。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Policy 政策