Governments and cybersecurity experts have consistently warned organizations against paying ransom demands to hackers, emphasizing that such payments only embolden criminals by funding further cyberattacks. A recent report from cybersecurity company Proofpoint reinforces this stance, revealing that more than one-third of companies who paid a ransom faced repeat extortion demands from the same threat actors. This data highlights the flawed notion that paying off hackers will end an extortion situation, as it often leads to ongoing victimization.
Proofpoint’s findings illustrate how ransomware and extortion tactics have shifted from single-pay transactions to multifaceted threats where hackers use various forms of pressure, such as threatening to release stolen data publicly, to maintain leverage over victims. Despite promises by criminals to delete stolen information after ransom payments, evidence from incidents like the 2026 Klue hack shows that data may still be retained and subsequently exposed or used for additional extortion attempts. This growing trend means victims remain at risk even after settling initial demands.
High-profile cases demonstrate the complexity and persistence of ransomware extortion schemes. For instance, the 2024 attack on Change Healthcare involved multiple criminal factions demanding separate ransoms for stolen medical data pertaining to almost 192 million Americans. Payments to different hacker groups illustrate how cybercriminals collaborate yet also compete, increasing challenges for victims to resolve these attacks through negotiations or payments alone. Such situations highlight the limitations and dangers in relying on ransom payments as a resolution strategy.
Law enforcement operations, such as the 2024 crackdown on the LockBit ransomware gang, have confirmed that criminals often retain access to victims’ data despite ransom settlements. This ongoing data retention ensures hackers have continued bargaining power, effectively making ransom payments a temporary reprieve rather than a permanent fix. The overarching message for businesses facing cyber extortion is clear: paying ransoms may invite repeated attacks, underscoring the importance of robust cybersecurity defenses and incident response plans over negotiations with criminals.
Start the discussion with a take, question, or market read.