Organisations that pay a cyber ransom following an attack are significantly more likely to face subsequent extortion demands, according to a recent report by cybersecurity firm Proofpoint. The findings reinforce a long-held understanding among security researchers and network defenders that negotiating with cybercriminals rarely results in a clean break, as there is little incentive for the attackers to leave victims alone.
Proofpoint's survey of 953 companies revealed that more than one-third of those that paid an initial ransom were later targeted with a second extortion attempt. This data suggests a shift in cybercriminal tactics, moving from single ransom transactions to more complex extortion efforts that leverage multiple forms of pressure, such as threatening to publicly release stolen data.
While hackers frequently claim they will delete or destroy stolen data once a payment is made, past incidents have demonstrated this is often not the case. For example, last month, market research firm Klue experienced a hack that exposed customer data. Despite striking a deal with the hackers, who claimed to have deleted the information, the company later admitted that a separate criminal group had accessed a sample of the stolen data, leaving its customers vulnerable to future demands.
A similar scenario unfolded in 2024 with Change Healthcare, where a Russian-speaking ransomware group stole health and medical data belonging to a vast number of individuals in America. Amid internal disputes among the cybercriminals, Change Healthcare ended up paying separate ransoms to both the primary group and its affiliates in an attempt to prevent the sensitive medical information from being published online.
UK law enforcement has also provided evidence supporting these suspicions. During efforts to dismantle the prolific LockBit ransomware gang in 2024, police discovered victims' stolen data still stored on LockBit's servers, long after those organisations had paid the demanded ransoms. This confirms the persistent risk of data retention by criminals, even post-payment.
These incidents underscore the consistent advice from governments and cybersecurity experts: paying ransoms not only emboldens criminals and funds future attacks but also offers no guarantee of data security or an end to the extortion. The evolving nature of these threats means organisations must prioritise robust preventative measures and comprehensive recovery plans over capitulating to demands.