(If not, why not?)
(Imho, it would make sense if only the state can pay ransoms)
Instead, you would pay (exhorbitant) consulting fees to a foreign-based "offensive security" entity, and most of the time get some sort of security report that says if you'd simply plug this and that holes, your systems would now be reasonably safe.
Lots of US based incident response companies handling ransomware payments, this isn’t the domain of some sketchy foreign offsec joints.