• 2 min read
Paying ransomware often brings a second demand
Proofpoint says more than a third of companies that paid a hacker’s ransom were hit again with another extortion demand.

Image: TechCrunch
Governments have long warned victims not to pay ransom demands, and new data from Proofpoint adds another reason: paying once often does not end the attack. In a report published Wednesday, the cybersecurity company said it surveyed 953 companies and found that more than one-third of businesses that paid a hacker’s ransom later faced a second extortion demand.
That lines up with what security researchers and defenders have argued for years: extortion gangs have little reason to negotiate in good faith when they can keep squeezing victims after a payout. According to Proofpoint, ransomware and extortion campaigns have shifted from a one-time payment model into multi-stage pressure tactics, including threats to leak stolen data even after money changes hands.
Recent cases show why. Last month, a hack at market research firm Klue exposed customer data, including information belonging to several cybersecurity firms. Klue said it reached a deal with the hackers, who claimed they had deleted the stolen files, but the company later acknowledged that a separate hacking group obtained a sample of that data, exposing customers to possible future extortion.
A similar episode hit Change Healthcare in 2024, when a Russian-speaking ransomware gang stole health and medical data on the majority of people in America — about 192 million people. During a dispute between the hackers and their affiliates, the company paid separate ransoms to both groups in an attempt to keep the data offline.
Law enforcement has also found evidence that gangs keep victim data after payment. During efforts to dismantle the LockBit ransomware gang in 2024, U.K. police said they discovered stolen victim data on LockBit’s servers long after those victims had already paid.

Recommended reading
Enterprise GenAI Can Speed Up Ransomware Attacks
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechCrunch


