Paying ransom demands emboldens attackers and often leads to more extortion attempts. A Proofpoint report reveals the troubling reality for victims.
If you think paying a hacker’s ransom is the end of your troubles, think again. Recent findings from Proofpoint reveal that one-third of companies that settle with attackers face additional extortion attempts soon after. So much for putting an end to your nightmare; paying won’t just let you breathe easier. Instead, it can embolden those malicious actors to keep coming back for more. The landscape here is shifting, and it’s high time organizations realize the stakes.
In a world where ransomware tactics are escalating, the act of paying a ransom isn’t a cure-all. Hackers have evolved to leverage various pressure points beyond mere file encryption, such as threatening to release sensitive data publicly. We've seen this play out numerous times. Take the case of market research firm Klue: after paying off the original hackers, they found themselves under threat again, facing additional harassment. Change Healthcare went through a similar saga, shelling out ransoms to multiple groups amid ongoing breaches. This isn’t a one-off; it’s a pattern that organizations must recognize.
Even when companies believe they’ve dodged a bullet by paying, evidence suggests that the data can remain with hackers long after the ransom is settled. A crackdown on the notorious LockBit ransomware gang by U.K. law enforcement unearthed victims' data sitting dormant on servers, further affirming what security professionals have long suspected. This isn’t merely an inconvenience; it’s an operational risk that can snowball into a catastrophic breach down the line. The message here is clear: paying up does not guarantee that your information cuts ties with the criminals.
Why give hackers the upper hand? Every payment made sends a signal that the business is willing to negotiate with extortionists. While it may seem like a short-term solution, the reality is that it invites a cycle of further attempts at coercion. Organizations need to be aware that with every payment made, they raise the stakes for others in their industry. Breaches aren’t just lessons for the victim; they serve as datasets for the attackers, informing their next moves against other targets. As such, paying could inadvertently spread the problem across the corporate landscape.
So, what are your options? You could try the gamble of negotiating, but the evidence speaks volumes: that doesn’t work well either. Here’s the truth: developing a robust incident response plan that includes containment, triage, and secure data handling is the only sustainable strategy. This means investing in prevention measures that go beyond just a reactionary stance when an incident occurs. Examine your current security posture, ensure regular training for employees, and have an incident response team ready to act. Plan for the worst so that when incidents do arise, you won’t be cornered into making a payment.
Paying ransoms isn’t just a poor financial choice; it's a strategic misstep that can leave organizations exposed to relentless harassment from attackers. With findings from Proofpoint making the consequences glaringly obvious, companies must resist the dangerous allure of paying off criminals. Instead, fortify your defenses. Investing in preventative strategies and clear incident response workflows is the only way to stop the revolving door of extortion. Nobody wins when you feed the beast.
This perspective is generated from an AI columnist's point of view.
https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more