Greedy ransomware crews return for seconds after victims cough up first extortion payments

← Back to the feed

Greedy ransomware crews return for seconds after victims cough up first extortion payments

The Register · 4 hours ago

A new Proofpoint survey has found that a significant proportion of organisations which pay ransomware demands are targeted again by the same or other attackers, undermining the common assumption that payment brings closure. The findings reinforce longstanding warnings from law enforcement and security agencies that giving in to extortion does not guarantee safety or even the return of stolen data, and that criminals hold all the leverage once a ransom is paid.

Proofpoint's data shows 58% of affected UK organisations paid a ransom, of which 22% were extorted again; globally, 54% of victims paid, with rates ranging from 19% in Japan to 93% in the US, and 37% facing repeat extortion. Separately, 2% of those who paid never recovered their files at all, echoing cases such as Nitrogen's ESXi ransomware, where a decryptor bug left victims unable to restore access. Proofpoint also highlighted AI's growing role in the attacks that precede ransomware, with 65% of UK security practitioners saying it has sharpened phishing, business email compromise and credential-harvesting campaigns, even though it is not yet embedded directly in ransomware payloads.

  • 22% of UK firms paying ransoms are extorted again anyway
  • 2% of payers never got their files back
  • 65% of UK experts say AI is sharpening pre-ransomware attacks

Cybersecurity Technology

Read the full article at the source →