Proofpoint survey reveals Ransomware Gangs frequently Re-Extort Victims after initial Ransom Payment | #ransomware | #cybercrime


A recent cybersecurity survey conducted by Proofpoint has reinforced a warning that law enforcement agencies have been issuing for years: paying a ransomware demand does not necessarily bring an attack to an end. Instead, organizations that comply with cybercriminals’ demands often become repeat targets, exposing themselves to multiple rounds of extortion and greater financial losses.

For several years, agencies such as the U.S. Federal Bureau of Investigation (FBI) and Europol have consistently advised businesses against paying ransomware operators. Their guidance is based on extensive investigations showing that ransom payments not only fund organized cybercrime but also encourage threat actors to continue attacking the same victims or launch similar campaigns against others. Paying a ransom provides cybercriminals with both financial resources and the confidence that their victims may be willing to negotiate again in the future.

Proofpoint’s latest survey highlights this growing concern. According to the research, 58 percent of surveyed businesses in the United Kingdom admitted to paying a ransom following a ransomware attack. More concerningly, over 22 percent of those organizations reported being extorted two or three additional times after their initial payment. These findings suggest that many ransomware groups maintain records of organizations that have previously paid and deliberately revisit them for future extortion attempts.

The survey also revealed notable regional differences in ransomware payment trends. More than 93 percent of affected organizations in the United States reportedly chose to pay ransom demands, while approximately 19 percent of victims in Japan followed the same path. Researchers believe these differences are influenced by several factors, including cyber insurance policies, regulatory obligations, incident response maturity, backup and disaster recovery capabilities, organizational culture, and varying attitudes toward negotiating with cybercriminals.

Modern ransomware attacks have evolved far beyond simple file encryption. Today’s ransomware gangs frequently adopt double and even triple extortion strategies. Before encrypting systems, attackers steal sensitive corporate data and threaten to publish confidential information on dark web leak sites if payment is refused. Some groups also contact customers, business partners, or the media to increase pressure on victims, while others launch distributed denial-of-service (DDoS) attacks or threaten regulatory exposure. Such tactics significantly increase reputational, legal, and financial risks for affected organizations.

Cybersecurity experts believe these aggressive pressure tactics often discourage victims from reporting incidents to law enforcement agencies or engaging digital forensic and incident response (DFIR) specialists. Instead, many organizations quietly negotiate with attackers in hopes of restoring operations quickly, inadvertently strengthening the ransomware economy.

International law enforcement efforts continue to disrupt major ransomware operations. Initiatives such as Operation Cronos, which targeted the notorious LockBit ransomware syndicate, resulted in infrastructure seizures, arrests, and intelligence gathering. However, cybersecurity researchers warn that the ransomware ecosystem remains highly resilient. As established gangs are dismantled, new ransomware-as-a-service (RaaS) groups continue to emerge, recruiting affiliates and launching sophisticated attacks at an alarming pace.

Another troubling finding from the Proofpoint survey is that paying a ransom offers no guarantee of successful data recovery. More than 2 percent of victims reported that they failed to recover their encrypted files despite transferring the requested payment. Among the most affected were victims of Nitrogen’s ESXi ransomware, demonstrating that attackers may simply disappear after receiving funds or provide defective decryption tools.

Looking ahead, Proofpoint warns that artificial intelligence is likely to accelerate the sophistication of cyberattacks. AI-powered phishing campaigns, business email compromise (BEC), credential harvesting, malicious email attachments, and highly personalized social engineering attacks are expected to become more convincing and scalable. As ransomware operators increasingly integrate AI into their attack chains, organizations will need to strengthen cyber resilience through zero-trust security, employee awareness training, multi-factor authentication, regular offline backups, endpoint detection and response (EDR), and proactive threat intelligence to reduce the likelihood of becoming repeat victims.

Join our LinkedIn group Information Security Community!



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW