If you pay a hacker's ransom, chances are that they'll come back for more
Companies that pay ransomware demands are more likely than not to be targeted again by the same attackers, according to a new report from cybersecurity firm Proofpoint, which surveyed 953 companies and found that over…
Companies that pay ransomware demands are more likely than not to be targeted again by the same attackers, according to a new report from cybersecurity firm Proofpoint, which surveyed 953 companies and found that over one-third of those that paid a ransom subsequently received a second extortion demand.
Why negotiating rarely ends the problem
The finding reinforces a principle security researchers have long warned about: paying a ransom does not reliably make the problem go away, because "there's no incentive for the other side to actually walk away" once a victim has demonstrated a willingness to pay. Once attackers know a target will negotiate and pay, that target becomes a more attractive, not less attractive, mark for repeat extortion.
From single payoffs to sustained leverage
Proofpoint's research points to a structural shift in how ransomware operations work. Where early ransomware attacks were largely single-transaction events — encrypt data, demand payment, provide a decryption key — modern operations increasingly retain copies of stolen data even after a ransom is paid, using the threat of public release as an additional, renewable source of leverage that can be activated again months or years later.
Real-world cases that prove the pattern
The report cites several concrete examples of this dynamic playing out. In the Klue breach earlier this year, attackers who had struck a deal and claimed to have deleted stolen data were later found to have let competitors access portions of that same information, despite the earlier agreement. In the 2024 Change Healthcare breach, the company ended up paying separate ransoms to two different criminal groups in an attempt to prevent the exposure of medical data belonging to 192 million Americans — a case widely cited as an example of how quickly a single breach can spiral into multiple, overlapping extortion attempts. And in the LockBit case, also from 2024, UK law enforcement discovered that victims' stolen data remained stored on the group's servers long after affected organizations had already paid to have it removed.
The takeaway for organizations
Taken together, Proofpoint's findings and these case studies point to the same conclusion: promises from ransomware operators to delete stolen data after payment should not be treated as reliable, regardless of what is agreed to during negotiations. For organizations weighing whether to pay following an attack, the research suggests that doing so buys, at best, temporary relief rather than genuine closure, and in more than a third of cases, simply invites a second round of extortion from the same attacker.
What security experts recommend instead
Given that finding, cybersecurity practitioners increasingly frame ransomware preparedness less around whether to pay if attacked and more around reducing the odds of a successful breach in the first place: maintaining offline, tested backups that don't depend on paying anyone to restore operations, segmenting networks so a single compromised system can't cascade into a full shutdown, and treating any ransomware incident as a full data-breach event requiring notification and remediation regardless of whether a ransom is ultimately paid. Proofpoint's findings add empirical weight to that guidance, showing concretely that the alternative — negotiating and paying — carries a documented, substantial risk of simply setting up the next extortion attempt rather than closing the incident out.
Comments
No approved comments yet.


