Ransomware operators are abandoning any pretence of honour among thieves, with new evidence showing they routinely demand second payments from victims who have already coughed up initial ransoms. Security firm Proofpoint has documented cases where criminals return to organisations that paid the first demand, threatening to leak stolen data unless a further sum is handed over. In some instances, victims never saw their files again despite complying with the original extortion.
The trend, described by researchers as 'double-dipping', marks an escalation in cybercriminal tactics that has serious implications for UK businesses. Traditional ransomware attacks encrypted files and demanded payment for decryption keys. But criminals now routinely exfiltrate data before encrypting systems, giving them leverage to extort victims repeatedly. 'There is no honour among thieves,' one Proofpoint analyst noted, adding that organisations cannot trust that paying a ransom will resolve the incident.
For UK companies, the findings underscore the importance of robust backup strategies and incident response plans. The Information Commissioner's Office (ICO) has previously warned that paying ransoms does not absolve organisations of their data protection obligations under UK GDPR. Meanwhile, the EU AI Act, which came into force earlier this year, imposes additional transparency requirements on AI-driven security tools that many firms rely on to detect ransomware.
UK businesses face a difficult calculation. Paying a ransom may seem the fastest route to recovery, but Proofpoint's research suggests it can lead to further demands and no guarantee of data restoration. The National Cyber Security Centre (NCSC) advises against paying ransoms, arguing it fuels the criminal ecosystem. However, for small and medium-sized enterprises without dedicated cybersecurity teams, the pressure to restore operations quickly can be overwhelming.
Experts say the double-dip phenomenon is likely to accelerate as ransomware-as-a-service operations become more sophisticated. 'Criminals are optimising their revenue streams,' said a cybersecurity analyst at a London-based consultancy. 'If a victim pays once, they are flagged as willing to pay again.' The economic impact on UK plc could be significant, with recovery costs, regulatory fines, and reputational damage mounting for each incident.