Governments have long warned against paying a hacker’s ransom demands, arguing that doing so only allows criminals to profit from their cyberattacks and fund the next one. There’s another reason, too: hackers are unlikely to leave you alone if you pay once, and many will come back demanding more. In a report released Wednesday, cybersecurity
Governments have long warned against paying a hacker’s ransom demands, arguing that doing so only allows criminals to profit from their cyberattacks and fund the next one. There’s another reason, too: hackers are unlikely to leave you alone if you pay once, and many will come back demanding more.
In a report released Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that more than a third of companies that paid a hacker’s ransom were hit by a second extortion demand. The findings underscore the long-held understanding among security researchers and network defenders that it is impossible to negotiate in good faith with an extortion racket because there is no incentive for the other party to actually back away.
Proofpoint data shows that ransomware and extortion attacks have evolved from a single transaction in which hackers got paid once and moved on, to an effort that uses multiple forms of leverage, such as retaining stolen data under the threat of public disclosure.
While hackers have claimed in the past that they will delete or destroy a victim’s stolen data, past incidents have shown that is not the case.
Last month, an attack on market research company Klue exposed data belonging to its clients, including several cybersecurity companies. The company said it reached a settlement with the hackers, who claimed to have deleted the data, but the company later admitted that a separate hacking group stole a sample of the company’s stolen data, leaving its customers exposed to possible future extortion claims.
A similar situation occurred in Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the medical and health data of the majority of the US population, some 192 million people. Amid a dispute between hackers and their affiliates (criminal groups often outsource attacks), Change Healthcare paid separate ransoms to both criminal groups to keep sensitive medical data off the Internet.
Security researchers have long suspected that ransomware gangs and extortion networks will retain a victim’s stolen data even after payment is made. UK law enforcement confirmed this during their takedown efforts of the prolific LockBit ransomware gang in 2024. Police said they found victims’ stolen data stored on LockBit servers long after the ransom had been paid.
When you buy through links in our articles, we may earn a small commission. This does not affect our editorial independence.
Keep following us for the latest insights.

















