Governments have long warned against paying a hacker’s ransom, arguing that doing so only allows criminals to profit from their cyberattacks and fund the next one. There’s another reason, too: hackers are unlikely to leave you alone if you pay once, and many will come back asking for more.
In a report published Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and I establish that over a third of companies that paid a hacker’s ransom were hit with a second extortion demand. The findings underscore the longstanding understanding among security researchers and network defenders that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away.
Proofpoint’s data shows that ransomware and extortion attacks have evolved from a single transaction where hackers were paid once and moved on to an effort using multiple forms of leverage, such as holding stolen data under threat of public release.
While hackers have previously claimed to delete or destroy the victim’s stolen data, past incidents have shown that this is not the case.
Last month, a hack at market research firm Klue exposed data belonging to its clients, including several cybersecurity firms. The company said it had reached an agreement with the hackers, who claimed to have deleted the data, but the company later admitted that a separate hacking group leaked a sample of the company’s stolen data, leaving its customers exposed to possible future extortion demands.
A similar situation happened to Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, about 192 million people. Amid conflict between hackers and their affiliates (criminal groups often subcontracting attacks), Change Healthcare paid separate ransoms to both criminal groups to keep sensitive medical data off the Internet.
Security researchers have long suspected that ransomware gangs and extortion rackets will keep the victim’s stolen data, even after payment. British law enforcement confirmed this during their takedown efforts targeting the prolific LockBit ransomware gang in 2024. Police said they found stolen victim data stored on LockBit’s servers long after they had paid the ransom.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
