Proofpoint’s latest survey reveals that more than one‑third of firms that paid a ransom faced a second extortion request. The finding underscores that paying ransoms fuels future cyber‑attacks rather than ending them.

Key Takeaways (मुख्य बिंदु)

  • Over one‑third of surveyed companies received a follow‑up extortion demand after paying.
  • Hackers often retain stolen data even after a ransom is paid.
  • Paying encourages additional cyber‑attacks and financial loss.

Proofpoint’s report, released on Wednesday, surveyed 953 organizations and found that 33% of those that paid a hacker’s ransom were hit with a second extortion demand. The data reinforces the long‑standing belief among security experts that negotiating in good faith with extortion gangs is futile, as attackers are always incentivised to extract more money.

Historically, ransomware attacks were a one‑time transaction: pay once and the criminals disappear. Today, attackers use multiple levers, such as threatening to publish stolen data, to coerce victims into repeated payments.

"Paying a ransom provides only temporary relief; it never returns the data and fuels future attacks," says cybersecurity analyst Anita Singh.

Last month, market‑research firm Klue suffered a breach that exposed client data, including several cybersecurity firms. The company struck a deal with the attackers, who claimed to have deleted the data. However, a different hacking group later stole a sample of the same data, leaving customers vulnerable to further extortion attempts.

In 2024, Change Healthcare faced a similar scenario when a Russian‑speaking ransomware gang stole health records of roughly 192 million Americans. Amid disputes among the gang and its subcontracted affiliates, Change paid separate ransoms to both groups to keep the data off the internet.

UK law‑enforcement confirmed during the 2024 takedown of the prolific LockBit ransomware gang that victims’ stolen data remained on the gang’s servers long after ransom payments were made, proving that payment does not guarantee data removal.

Why This Matters (इसके मायने क्या हैं)

According to BozokMedia analysis, ransom payments not only cause immediate financial loss but also erode customer trust. When users realize their personal data remains at risk, they may abandon digital services, amplifying economic fallout.

The ripple effect extends to national security. Repeated extortion in critical sectors such as health, finance, and infrastructure forces governments to allocate additional resources for cybersecurity, heightening regulatory pressure.

Did You Know?: (क्या आप जानते हैं?) In the 1990s, ransomware typically vanished after a single payment, whereas modern ransomware campaigns now employ multi‑stage extortion that can last for months.

Frequently Asked Questions (अक्सर पूछे जाने वाले प्रश्न)

Does paying a ransom reduce the chance of future extortion?
No. Attackers often retain the data and may issue new demands even after payment.

What alternatives should companies consider instead of paying?
Implement robust backups, encryption, and an incident‑response plan to minimize the need for ransom payments.