Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Ransomware gangs double-dip as victims pay up but still lose data

Cybercriminals are increasingly extorting victims twice, with some never recovering their files even after paying, according to new research from security firm Proofpoint. The findings highlight a growing threat to UK businesses and public sector organisations.

  • Proofpoint reports ransomware gangs demanding second payments after initial ransoms are paid
  • Some victims who paid the first ransom never received decryption keys or regained access to their files
  • Double extortion tactics now include threatening to leak stolen data if additional payments are not made

Ransomware operators are abandoning any pretence of honour among thieves, with new evidence showing they routinely demand second payments from victims who have already coughed up initial ransoms. Security firm Proofpoint has documented cases where criminals return to organisations that paid the first demand, threatening to leak stolen data unless a further sum is handed over. In some instances, victims never saw their files again despite complying with the original extortion.

The trend, described by researchers as 'double-dipping', marks an escalation in cybercriminal tactics that has serious implications for UK businesses. Traditional ransomware attacks encrypted files and demanded payment for decryption keys. But criminals now routinely exfiltrate data before encrypting systems, giving them leverage to extort victims repeatedly. 'There is no honour among thieves,' one Proofpoint analyst noted, adding that organisations cannot trust that paying a ransom will resolve the incident.

For UK companies, the findings underscore the importance of robust backup strategies and incident response plans. The Information Commissioner's Office (ICO) has previously warned that paying ransoms does not absolve organisations of their data protection obligations under UK GDPR. Meanwhile, the EU AI Act, which came into force earlier this year, imposes additional transparency requirements on AI-driven security tools that many firms rely on to detect ransomware.

UK businesses face a difficult calculation. Paying a ransom may seem the fastest route to recovery, but Proofpoint's research suggests it can lead to further demands and no guarantee of data restoration. The National Cyber Security Centre (NCSC) advises against paying ransoms, arguing it fuels the criminal ecosystem. However, for small and medium-sized enterprises without dedicated cybersecurity teams, the pressure to restore operations quickly can be overwhelming.

Experts say the double-dip phenomenon is likely to accelerate as ransomware-as-a-service operations become more sophisticated. 'Criminals are optimising their revenue streams,' said a cybersecurity analyst at a London-based consultancy. 'If a victim pays once, they are flagged as willing to pay again.' The economic impact on UK plc could be significant, with recovery costs, regulatory fines, and reputational damage mounting for each incident.

Why this matters: UK businesses and public sector organisations are increasingly targeted by ransomware gangs that cannot be trusted to honour their end of a deal. Paying a ransom may no longer guarantee data recovery or prevent further extortion.

What this means for you: What this means for you: If your employer or a service you rely on is hit by ransomware, paying the ransom may not get your data back and could lead to further demands. Ensure your organisation has tested backups and a clear no-payment policy.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.