INTEL_REPORT
Ars Technica — Security · published 7/20/2026, 2:00:50 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Pay up or not? Ransomware surge has victims facing tough choices. Governments look at banning ransom payments in face of increasingly sophisticated threats. Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, fo…
https://arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices
sha256:61597403d8f08d0f4648046e7df3aa5a8b27c880a05e30244e35914b07fef744
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.