Key facts
- Over one-third of companies that paid a hacker's ransom demand were subsequently targeted with a second extortion attempt.
A Proofpoint report found over one-third of companies that paid a ransom demand were subsequently targeted with a second extortion attempt, highlighting the risks of negotiating with cybercriminals.

The findings suggest that paying ransoms does not guarantee an end to cyberattacks and may even increase a company's vulnerability to future extortion, potentially leading to greater financial and reputational damage.
Governments have long advised against paying ransom demands to hackers, citing that such payments fund future criminal activities and do not guarantee cessation of attacks. A new report from cybersecurity firm Proofpoint reveals an additional risk: companies that pay ransoms are frequently targeted again. The survey of 953 companies found that more than a third of those who paid a ransom demand were subsequently subjected to a second extortion attempt. This underscores the view among security experts that negotiating with extortion rackets is futile, as there is no incentive for criminals to cease their activities once a payment is made.
Proofpoint's findings indicate an evolution in ransomware and extortion tactics. Attacks are no longer typically single transactions; instead, they involve multiple forms of leverage, such as holding stolen data hostage with the threat of public disclosure. Historically, hackers have claimed to delete or destroy stolen data, but evidence suggests this is often not the case.
Recent incidents illustrate this pattern. Last month, market research firm Klue suffered a breach exposing customer data. Despite striking a deal with hackers who claimed to have deleted the data, a separate group later obtained a sample, leaving Klue's customers vulnerable to further extortion. Similarly, in 2024, Change Healthcare experienced a massive theft of sensitive medical data affecting approximately 192 million individuals. Amidst internal disputes among the cybercriminal groups involved, Change Healthcare paid separate ransoms to multiple entities to prevent the data from being released online.
Security researchers have long suspected that ransomware gangs retain victims' data even after payment. This suspicion was corroborated by UK law enforcement during their operations against the LockBit ransomware group in 2024. Police discovered that victims' stolen data was still stored on LockBit's servers long after the ransom payments had been made.