If you pay a hacker’s ransom, chances are that they’ll come back for more
A new report from cybersecurity firm Proofpoint reinforces long-standing warnings that paying a ransomware demand rarely ends a company's troubles, as attackers frequently return for further payments. This matters because it undermines the logic some organisations use to justify paying ransoms in the hope of quickly resolving an incident, showing instead that compliance can invite repeated extortion rather than closure.
Proofpoint surveyed 953 companies and found that more than a third of those which paid a ransom were subsequently hit with a second extortion demand. The report notes that attacks have shifted from one-off payments towards sustained leverage, such as retaining stolen data to threaten victims again later, even when hackers claim to have deleted it. Recent examples include market research firm Klue, whose stolen customer data resurfaced via a separate hacking group despite an apparent deal, and Change Healthcare, which paid two separate criminal groups in 2024 after a breach affecting roughly 192 million Americans. UK police also found LockBit ransomware gang servers still held victims' stolen data long after ransoms had been paid.
- Proofpoint: over a third of ransom-payers face a second extortion demand
- Hackers often keep stolen data even after being paid
- Change Healthcare and Klue breaches show repeat extortion in practice