Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Paying Cyber Ransom Often Leads to Repeat Attacks, Study Reveals

A new report highlights the high likelihood of repeat extortion demands after an initial ransom payment to hackers. Cybersecurity experts warn against negotiating with cybercriminals, as it rarely leads to a definitive end to threats.

  • Over one-third of companies paying a cyber ransom faced a second extortion demand.
  • Hackers often retain stolen data even after payment, using it for future leverage.
  • Law enforcement operations have confirmed that criminals keep victim data post-payment.
  • Governments consistently advise against paying ransoms, citing it funds further criminal activity.

Organisations that pay a cyber ransom following an attack are significantly more likely to face subsequent extortion demands, according to a recent report by cybersecurity firm Proofpoint. The findings reinforce a long-held understanding among security researchers and network defenders that negotiating with cybercriminals rarely results in a clean break, as there is little incentive for the attackers to leave victims alone.

Proofpoint's survey of 953 companies revealed that more than one-third of those that paid an initial ransom were later targeted with a second extortion attempt. This data suggests a shift in cybercriminal tactics, moving from single ransom transactions to more complex extortion efforts that leverage multiple forms of pressure, such as threatening to publicly release stolen data.

While hackers frequently claim they will delete or destroy stolen data once a payment is made, past incidents have demonstrated this is often not the case. For example, last month, market research firm Klue experienced a hack that exposed customer data. Despite striking a deal with the hackers, who claimed to have deleted the information, the company later admitted that a separate criminal group had accessed a sample of the stolen data, leaving its customers vulnerable to future demands.

A similar scenario unfolded in 2024 with Change Healthcare, where a Russian-speaking ransomware group stole health and medical data belonging to a vast number of individuals in America. Amid internal disputes among the cybercriminals, Change Healthcare ended up paying separate ransoms to both the primary group and its affiliates in an attempt to prevent the sensitive medical information from being published online.

UK law enforcement has also provided evidence supporting these suspicions. During efforts to dismantle the prolific LockBit ransomware gang in 2024, police discovered victims' stolen data still stored on LockBit's servers, long after those organisations had paid the demanded ransoms. This confirms the persistent risk of data retention by criminals, even post-payment.

These incidents underscore the consistent advice from governments and cybersecurity experts: paying ransoms not only emboldens criminals and funds future attacks but also offers no guarantee of data security or an end to the extortion. The evolving nature of these threats means organisations must prioritise robust preventative measures and comprehensive recovery plans over capitulating to demands.

Why this matters: This report highlights the critical risks for UK businesses and public sector organisations facing ransomware attacks, demonstrating that paying a ransom is often a temporary and ineffective solution. It underscores the importance of strong cybersecurity defences and incident response plans to protect sensitive data and avoid repeat victimisation.

What this means for you: What this means for you: As a UK citizen, this impacts you through potential disruptions to services you rely on, such as healthcare or financial institutions, if they become victims of repeat attacks. It also increases the risk of your personal data being compromised and used in future extortion attempts if organisations you interact with pay ransoms without securing your information.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.