Cybersecurity experts have repeatedly advised organizations not to pay ransomware demands. A new report from cybersecurity company Proofpoint now provides fresh evidence supporting that advice: paying hackers often doesn’t end the attack it can actually invite more extortion.

According to Proofpoint’s latest survey of 953 organizations, more than one-third of businesses that paid a ransom later received another extortion demand from cybercriminals. The findings suggest that many ransomware groups continue targeting victims even after receiving payment.

Paying Doesn’t Guarantee Safety

For years, governments and cybersecurity agencies have warned that paying ransom encourages cybercriminals by funding future attacks. Proofpoint’s research adds another concern: hackers may view paying organizations as easy targets and return with additional demands.

Modern ransomware attacks have also evolved. Instead of simply encrypting files, many attackers now steal sensitive company data and threaten to publish it online unless additional payments are made.

Stolen Data May Never Be Deleted

Cybercriminals often promise to delete stolen information after receiving payment, but several recent incidents show those promises cannot be trusted.

One example involved market research company Klue, which reportedly reached an agreement with hackers after a cyberattack. However, the company later disclosed that another hacking group had obtained a portion of the stolen data, leaving customers exposed to future extortion attempts.

Another major case occurred during the 2024 Change Healthcare ransomware attack, where sensitive medical information affecting approximately 192 million people was stolen. Reports indicate that multiple criminal groups demanded payments during the incident, forcing the company to negotiate with more than one cybercrime organization.

Law Enforcement Findings Support the Warning

Security researchers have long suspected that ransomware gangs retain stolen data even after victims pay.

That concern was reinforced during international law enforcement operations against the LockBit ransomware group in 2024. Investigators reportedly discovered victim data still stored on LockBit’s infrastructure long after ransom payments had been made.

Growing Risks for Businesses

The latest findings highlight why cybersecurity experts continue recommending prevention over negotiation. Organizations are encouraged to:

  • Maintain secure offline backups.
  • Deploy strong endpoint protection.
  • Train employees to recognize phishing attacks.
  • Enable multi-factor authentication (MFA).
  • Develop an incident response plan before an attack occurs.

Stay updated with the VitalStack.

Read More on VitalStack

Enjoyed this article?

Subscribe for weekly deep-dives on AI and health — straight to your inbox.