A ransomware payment should be treated as a failed emergency option, not a recovery strategy, because Proofpoint’s latest survey shows the bargain often doesn’t end the threat. It reopens it.

Ransomware Payment Trap Pulls Victims Back for More
XOOMAR Intelligence
Analyst Take
According to TechCrunch, Proofpoint surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom later faced a second extortion demand. That should settle the boardroom debate. Paying may buy time. It does not buy trust, finality, or control.
A ransomware payment turns one breach into a recurring negotiation
Governments have long warned victims not to pay hacker ransom demands because the money rewards criminal activity and funds the next attack. Proofpoint’s data adds a sharper business reason: the attacker may not go away.
The old mental model of ransomware was too tidy. Hackers break in, lock files, demand money, get paid, move on. That was always optimistic. Proofpoint’s findings point to a harsher model, where attackers stack pressure by holding stolen data, threatening publication, and returning for more after the first payment proves the victim can be moved.
That changes the decision. A ransomware payment is not just an IT expense. It is a signal sent during maximum organizational stress. The victim says, in effect, that money can be extracted when operations, privacy, or reputation are under pressure.
XOOMAR’s view: executives should still retain room for genuine emergency exceptions. But they should stop pretending payment is a clean exit. The data says otherwise.
Paid victims give extortionists a reason to ask again
The source material does not prove that every ransomware gang keeps formal “customer lists,” and we shouldn’t invent that. But the economic logic supported by the reporting is blunt enough: if payment works once, the criminal side has little incentive to treat the matter as closed.
Proofpoint’s findings reinforce what security researchers and network defenders have argued for years. You cannot negotiate in good faith with an extortion racket because the other side is not bound by reputation, contract, court, or future commercial relationship. The attacker already has the victim’s data or access. The attacker also controls whether to delete, sell, share, or threaten to publish what was stolen.
The Klue incident shows the problem. TechCrunch reported that a hack at the market research firm exposed customer data, including data belonging to several cybersecurity firms. Klue said it reached a deal with hackers who claimed to have deleted the data. Later, the company conceded that a separate hacking group had obtained a sample of the stolen data, leaving customers exposed to possible future extortion demands.
That is the central lesson. Even if one group says the data is gone, the victim cannot verify the full chain of custody.
The deletion promise is weaker than executives want to believe
Attackers often claim they will delete or destroy stolen data after payment. Past incidents in the supplied reporting show why that promise deserves little weight.
Change Healthcare faced a similar breakdown in 2024 after a Russian-speaking ransomware gang stole health and medical data affecting 192 million people, described in the source material as the majority of people in America. Amid a dispute between the hackers and their affiliates, Change Healthcare paid separate ransoms to both groups to keep sensitive medical data off the internet.
Then came LockBit. During U.K. law enforcement’s 2024 takedown of the prolific ransomware gang, police said they found victims’ stolen data stored on LockBit’s servers long after those victims had paid.
| Attacker promise | Reported reality from supplied cases |
|---|---|
| Data deletion | LockBit victims’ stolen data was found stored after ransom payment |
| One-and-done settlement | Over one-third of paying companies faced a second extortion demand |
| Control after payment | Klue customers remained exposed after another group obtained a sample of stolen data |
| Single criminal counterparty | Change Healthcare paid separate ransoms amid a dispute between hackers and affiliates |
The Register’s related coverage of Proofpoint’s findings added another hard edge: 2 percent of victims that paid never recovered their files at all. That figure is small, but it destroys the fantasy that payment guarantees restoration.
A ransom can create the appearance of closure while the real problem remains unresolved: the victim has already lost control of data, and the criminal side may still have material to use.
Boards should fund resilience before the crisis room starts writing checks
Here is the governance failure: too many ransomware decisions are made when the organization has the least room to think clearly. The systems are down. Customers are angry. Lawyers are on calls. Executives want the pain to stop.
That is exactly when the attacker has the strongest hand.
XOOMAR analysis: the right time to decide ransom policy is before an attack. The right time to test backups is before encryption. The right time to define executive authority is before a threat actor starts a countdown.
This is where the conversation should move from payment ethics to operational discipline:
- Backups: Keep them isolated enough that attackers cannot simply encrypt the recovery path too.
- Restoration: Test recovery, not just backup creation.
- Identity: Treat stolen credentials as a business risk, not a help desk nuisance.
- Response drills: Run tabletop exercises that include legal, communications, finance, and leadership.
- Patch discipline: Track exposed enterprise systems before they become entry points. For readers following that side of the problem, see our coverage of ServiceNow CVE-2026-6875 Hands Hackers an RCE Path.
Markets readers understand pre-commitment. You set risk limits before volatility arrives, not after the position is already moving against you, a theme familiar from our coverage of Oil Rally Drags USD/CAD Toward 1.4100 as Loonie Hits Back. Ransomware needs the same discipline. Decide before panic prices the decision for you.
The hardest cases are real, but they can’t become the default
The strongest counterargument is not theoretical. Some victims face brutal choices.
A hospital, municipality, logistics operator, or small business may decide that paying is the fastest way to restore systems or reduce harm. A rigid moral lecture is useless when patient care, payroll, or critical services are on the line. Executives in that position are not choosing between good and bad. They are choosing between bad options under pressure.
But emergency exceptions cannot become standard policy. If they do, ransomware operators get a repeatable business model, and Proofpoint’s survey suggests paying victims may still face more demands.
Every payment should trigger three things:
- Mandatory internal review: Why was payment considered necessary?
- Forensic scrutiny: What data was taken, and what access remains?
- Funded remediation: What changes make a second demand harder to send?
A ransom paid without a resilience plan is just a down payment on the next crisis.
Stop treating payment as the cleanest exit
The practical prescription is simple and uncomfortable: assume the attacker may lie. Assume stolen data may persist. Assume payment may not end the incident.
Executives should set a ransomware policy before they need it, rehearse the decision chain, isolate backups, test restoration, and give security teams authority before the room fills with panic. Insurers, regulators, and boards should stop treating payment as the neatest exit and start asking whether the organization can prove basic recovery readiness.
The next phase of ransomware will be judged less by whether companies can negotiate and more by whether they can refuse to negotiate from weakness.
The cheapest ransom is the one attackers never get to ask for. The second-cheapest is the one they learn won’t be paid again.
The Bottom Line
- Proofpoint surveyed 953 companies and found paying a ransom can lead to renewed extortion pressure.
- Over one-third of companies that paid later received a second demand, undermining payment as a reliable recovery plan.
- The findings give executives a business reason, not just a policy reason, to avoid treating ransom payment as closure.
Ransomware Payment: Perceived Benefit vs. Reported Risk
| View of Payment | What the Article Says |
|---|---|
| Recovery strategy | Proofpoint’s survey suggests payment often does not end the threat. |
| Emergency exception | Executives may need rare exceptions, but should treat payment as a failed last resort. |
| Clean exit | Over one-third of paying companies later faced a second extortion demand. |
Sources
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
CybersecurityFairlife Ransomware Attack Freezes Coca-Cola Dairy Lines
A ransomware attack halted Fairlife's US production, turning Coca-Cola's cyber incident into an investor-visible operations risk.
CybersecurityFairlife Ransomware Attack Freezes US Dairy Production
A ransomware attack forced Coca-Cola to halt Fairlife's U.S. dairy production, with no restart date and Canada spared so far.
CybersecurityRansomware Groups Slip the Net With Serial Rebrands
Ransomware crews are rebranding faster as attacks rise, forcing defenders to track operators, not names.
Cybersecurity70-Month Sentence Exposes Ransomware Negotiator Betrayal
A negotiator got 70 months for helping BlackCat squeeze victims, showing how insider access can turn ransomware response against clients.
CybersecuritySelf-Destructing Mistic Backdoor Hides Ransomware Footholds
Mistic runs payloads in memory, then erases itself, giving suspected access brokers cleaner footholds for ransomware crews.
TechnologyInstagram Replace Audio Saves Old Posts From Reposts
Instagram now lets creators swap music on old feed posts and carousels without wiping likes, comments, shares, or reach.
Technology17% Leaner Gemini 3.6 Flash Squeezes AI Agent Costs
Google’s new Gemini Flash lineup targets agent costs, speed and security with separate models instead of one default choice.
TechnologyMissing Gemini 3.5 Pro Overshadows New Gemini Models
Google shipped cheaper Flash models, but the no-show Gemini 3.5 Pro is the real story for developers waiting on a capability leap.
Global TrendsUkraine Installs Mykhailo Drapatyi to Shake Up War Command
Mykhailo Drapatyi takes Ukraine's top command with reform hype and a brutal winter test ahead.
TradingInflation Shock Fails as Fear Knocks NZD/USD Lower
NZD/USD slipped despite hotter New Zealand inflation as traders chased US Dollar safety over RBNZ rate-hike bets.
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.