XOOMAR
Corporate cybersecurity scene showing repeated hacker ransom pressure and cracked digital shields.
CybersecurityJuly 22, 2026· 7 min read· By XOOMAR Insights Team

Ransomware Payment Trap Pulls Victims Back for More

Share
Updated on July 22, 2026

A ransomware payment should be treated as a failed emergency option, not a recovery strategy, because Proofpoint’s latest survey shows the bargain often doesn’t end the threat. It reopens it.

XOOMAR Intelligence

Analyst Take

58/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness100Source Trust90Factual Grounding89Signal Cluster20

According to TechCrunch, Proofpoint surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom later faced a second extortion demand. That should settle the boardroom debate. Paying may buy time. It does not buy trust, finality, or control.

A ransomware payment turns one breach into a recurring negotiation

Governments have long warned victims not to pay hacker ransom demands because the money rewards criminal activity and funds the next attack. Proofpoint’s data adds a sharper business reason: the attacker may not go away.

The old mental model of ransomware was too tidy. Hackers break in, lock files, demand money, get paid, move on. That was always optimistic. Proofpoint’s findings point to a harsher model, where attackers stack pressure by holding stolen data, threatening publication, and returning for more after the first payment proves the victim can be moved.

That changes the decision. A ransomware payment is not just an IT expense. It is a signal sent during maximum organizational stress. The victim says, in effect, that money can be extracted when operations, privacy, or reputation are under pressure.

XOOMAR’s view: executives should still retain room for genuine emergency exceptions. But they should stop pretending payment is a clean exit. The data says otherwise.


The source material does not prove that every ransomware gang keeps formal “customer lists,” and we shouldn’t invent that. But the economic logic supported by the reporting is blunt enough: if payment works once, the criminal side has little incentive to treat the matter as closed.

Proofpoint’s findings reinforce what security researchers and network defenders have argued for years. You cannot negotiate in good faith with an extortion racket because the other side is not bound by reputation, contract, court, or future commercial relationship. The attacker already has the victim’s data or access. The attacker also controls whether to delete, sell, share, or threaten to publish what was stolen.

The Klue incident shows the problem. TechCrunch reported that a hack at the market research firm exposed customer data, including data belonging to several cybersecurity firms. Klue said it reached a deal with hackers who claimed to have deleted the data. Later, the company conceded that a separate hacking group had obtained a sample of the stolen data, leaving customers exposed to possible future extortion demands.

That is the central lesson. Even if one group says the data is gone, the victim cannot verify the full chain of custody.

The deletion promise is weaker than executives want to believe

Attackers often claim they will delete or destroy stolen data after payment. Past incidents in the supplied reporting show why that promise deserves little weight.

Change Healthcare faced a similar breakdown in 2024 after a Russian-speaking ransomware gang stole health and medical data affecting 192 million people, described in the source material as the majority of people in America. Amid a dispute between the hackers and their affiliates, Change Healthcare paid separate ransoms to both groups to keep sensitive medical data off the internet.

Then came LockBit. During U.K. law enforcement’s 2024 takedown of the prolific ransomware gang, police said they found victims’ stolen data stored on LockBit’s servers long after those victims had paid.

Attacker promise Reported reality from supplied cases
Data deletion LockBit victims’ stolen data was found stored after ransom payment
One-and-done settlement Over one-third of paying companies faced a second extortion demand
Control after payment Klue customers remained exposed after another group obtained a sample of stolen data
Single criminal counterparty Change Healthcare paid separate ransoms amid a dispute between hackers and affiliates

The Register’s related coverage of Proofpoint’s findings added another hard edge: 2 percent of victims that paid never recovered their files at all. That figure is small, but it destroys the fantasy that payment guarantees restoration.

A ransom can create the appearance of closure while the real problem remains unresolved: the victim has already lost control of data, and the criminal side may still have material to use.

Boards should fund resilience before the crisis room starts writing checks

Here is the governance failure: too many ransomware decisions are made when the organization has the least room to think clearly. The systems are down. Customers are angry. Lawyers are on calls. Executives want the pain to stop.

That is exactly when the attacker has the strongest hand.

XOOMAR analysis: the right time to decide ransom policy is before an attack. The right time to test backups is before encryption. The right time to define executive authority is before a threat actor starts a countdown.

This is where the conversation should move from payment ethics to operational discipline:

  • Backups: Keep them isolated enough that attackers cannot simply encrypt the recovery path too.
  • Restoration: Test recovery, not just backup creation.
  • Identity: Treat stolen credentials as a business risk, not a help desk nuisance.
  • Response drills: Run tabletop exercises that include legal, communications, finance, and leadership.
  • Patch discipline: Track exposed enterprise systems before they become entry points. For readers following that side of the problem, see our coverage of ServiceNow CVE-2026-6875 Hands Hackers an RCE Path.

Markets readers understand pre-commitment. You set risk limits before volatility arrives, not after the position is already moving against you, a theme familiar from our coverage of Oil Rally Drags USD/CAD Toward 1.4100 as Loonie Hits Back. Ransomware needs the same discipline. Decide before panic prices the decision for you.


The hardest cases are real, but they can’t become the default

The strongest counterargument is not theoretical. Some victims face brutal choices.

A hospital, municipality, logistics operator, or small business may decide that paying is the fastest way to restore systems or reduce harm. A rigid moral lecture is useless when patient care, payroll, or critical services are on the line. Executives in that position are not choosing between good and bad. They are choosing between bad options under pressure.

But emergency exceptions cannot become standard policy. If they do, ransomware operators get a repeatable business model, and Proofpoint’s survey suggests paying victims may still face more demands.

Every payment should trigger three things:

  • Mandatory internal review: Why was payment considered necessary?
  • Forensic scrutiny: What data was taken, and what access remains?
  • Funded remediation: What changes make a second demand harder to send?

A ransom paid without a resilience plan is just a down payment on the next crisis.

Stop treating payment as the cleanest exit

The practical prescription is simple and uncomfortable: assume the attacker may lie. Assume stolen data may persist. Assume payment may not end the incident.

Executives should set a ransomware policy before they need it, rehearse the decision chain, isolate backups, test restoration, and give security teams authority before the room fills with panic. Insurers, regulators, and boards should stop treating payment as the neatest exit and start asking whether the organization can prove basic recovery readiness.

The next phase of ransomware will be judged less by whether companies can negotiate and more by whether they can refuse to negotiate from weakness.

The cheapest ransom is the one attackers never get to ask for. The second-cheapest is the one they learn won’t be paid again.

The Bottom Line

  • Proofpoint surveyed 953 companies and found paying a ransom can lead to renewed extortion pressure.
  • Over one-third of companies that paid later received a second demand, undermining payment as a reliable recovery plan.
  • The findings give executives a business reason, not just a policy reason, to avoid treating ransom payment as closure.

Ransomware Payment: Perceived Benefit vs. Reported Risk

View of PaymentWhat the Article Says
Recovery strategyProofpoint’s survey suggests payment often does not end the threat.
Emergency exceptionExecutives may need rare exceptions, but should treat payment as a failed last resort.
Clean exitOver one-third of paying companies later faced a second extortion demand.
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Ransomware Gang Hacks ATF Investigation Database

The ransomware gang Qilin claims it hacked an ATF system containing information on investigation targets, forcing the agency to declare a major incident.

Aug 27, 20265 min
Close-up of a man with glasses and binary code projection, symbolizing cyber security.Cybersecurity

Insider Demands $7,540 For Cache Of Corporate Secrets

A data analyst contractor was sentenced to two years in prison for stealing employee data and trying to extort $2.5 million, but the company paid just $7,540 to

Aug 14, 20267 min
Close-up view of a mouse cursor over digital security text on display.Cybersecurity

Cyber Attackers Destroy Backups Before Demanding Ransom

Modern ransomware attacks deliberately destroy backup data first, forcing companies to shift from passive data copies to provable, automated recovery in hours,

Aug 11, 20266 min
Wooden letter blocks spelling 'CYBER SECURITY' on a wooden grid background for data protection themes.Cybersecurity

Security Teams Miss 77% of Critical Attack Techniques

A formal detection program typically covers only 23% of MITRE ATT&CK techniques, leaving a massive gap attackers exploit. Proactive threat hunting using a SIEM

Aug 13, 202613 min
Conceptual image showing the words 'Ethical Hacking' on a textured abstract background.Cybersecurity

Critical Gitea Bug Hijacks Systems for Crypto Mining

A critical Gitea vulnerability is under active attack, letting hackers hijack servers for cryptocurrency mining, confirmed by CISA's urgent patch order.

Aug 26, 20267 min
A futuristic tech event hall with glowing podiums and holographic displays, set for a major conference announcement.Technology

TechCrunch's Side Event Pitch Closes in 24 Hours

The deadline to apply to host a sponsored side event at TechCrunch Disrupt 2026 is tonight at midnight PT, offering approved organizers massive promotional acce

Sep 7, 20265 min
A futuristic smartphone displays a glowing digital rooster, illuminating a sleek, tech-focused workspace with cinematic lighting.Technology

Clucky Alarm App Forces You Awake With Rooster Crows

Clucky's new alarm app can't be snoozed; you must complete tasks like math problems or push-ups to stop a crowing rooster, for $40 a year.

Sep 5, 20265 min
The Eiffel Tower at dusk with cinematic lighting, representing a global news event and international connections.Global Trends

Eiffel Tower Shuts Over Staff Alleging Women Were Sidelined

In a dramatic protest, the Eiffel Tower closed after management allegedly sidelined female staff during a private visit by the Hindu group BAPS, triggering a ci

Sep 8, 20266 min
A parched, desolate French vineyard under a harsh, dusty orange heatwave sky, depicting extreme drought impacting wine harvest.Global Trends

French Wine Harvest Plummets to Historic 30-Year Low

France's 2026 wine harvest is forecast to drop to its lowest level in 30 years due to extreme heat and drought, with Champagne yields cut in half.

Sep 8, 20265 min
Split view of a digital finance app and a stock ticker in a modern Tokyo office, symbolizing interest rate decisions.Fintech

Japan's Growth Beat Voids BOJ's Final Rate Hike Excuse

Japan's revised GDP growth to 1.4% provides the Bank of Japan with the necessary cover to proceed with a widely expected interest rate hike in September, shifti

Sep 8, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.