A new industry survey reveals that paying ransoms often triggers fresh extortion and prolonged exposure, raising urgent questions about recovery strategies and law enforcement roles.
Government and intergovernmental agencies warn against paying ransom to criminals for hacker demands, explaining that such a step fuels crime and funds future attacks. In addition, there is another reason: when payments are made upfront, the attackers come back again with new demands.
On Wednesday, a report from cybersecurity company Proofpoint was released: among 953 surveyed companies, more than a third of those who paid the ransom encountered demands from the attackers again. These findings underscore the prevailing view among experts: dealing with extortionists does not motivate attackers to change their behavior and does not reduce the threat of repeated pressure.
Proofpoint data indicate that ransom-based attacks are evolving: this is no longer a one-off financial payout, but a multi-faceted pressure campaign that prompts attackers to retain stolen data and threaten to publish it.
Examples and Consequences
Last month, a cyberattack on Klue exposed client data, including some companies in the cybersecurity sector. The company said it had reached an agreement with hackers who claimed to have deleted the data, but later confirmed that another group of attackers downloaded part of the stolen material, leaving clients at risk of another round of extortion.
A similar story occurred with Change Healthcare in 2024: a Russian-speaking ransomware group stole the medical data of the majority of Americans, about 192 million people. Because of disputes between attacker groups, Change Healthcare paid ransom to separate groups to avoid exposing sensitive data on the network.
During the investigation into the well-known LockBit group in 2024, British authorities confirmed: the stolen data were kept on the group’s servers for a long time after victims were offered payment.
These findings indicate that paying the ransom does not guarantee an end to the pressure, and repeated demands by attackers remain a real threat. A systematic approach to countering these threats includes restoring data from backups, strengthening defenses, isolating vulnerable systems, active cooperation with law enforcement, and enhanced threat monitoring.
Experts advise focusing on restoring information from backups, strengthening protections, and preparedness for incidents instead of paying the ransom. This approach does not reduce the risk of repeated attacks and may lead to additional costs and reputational losses. It is also important to develop clear incident response plans and strengthen threat monitoring to reduce the time from detection to neutralization of the threat.
