Paying Ransom Often Leads to Repeat Cyberattacks

Organizations that succumb to ransomware demands often find themselves targeted again, sometimes by the same attackers. A recent survey by cybersecurity firm Proofpoint, involving 953 companies, revealed that over one-third of those who paid a ransom faced subsequent extortion attempts. This underscores the longstanding advice from security experts: paying a ransom does not guarantee safety and may, in fact, invite further attacks.

Ransomware tactics have evolved beyond simple data encryption. Attackers now employ multiple forms of leverage, such as threatening to release stolen data publicly. Even when victims pay, there’s no assurance that the data will be deleted. For instance, in 2024, Change Healthcare paid ransoms to multiple criminal groups after a breach exposed sensitive medical data of approximately 192 million Americans. Despite the payments, the stolen data remained at risk, highlighting the unreliability of trusting cybercriminals to honor their promises.

Law enforcement agencies have found evidence that ransomware groups retain stolen data even after receiving payment. During operations against the LockBit ransomware gang in 2024, UK authorities discovered victims’ data stored on the gang’s servers long after ransoms were paid. This indicates that paying does not ensure the destruction of stolen information.

Moreover, paying a ransom can mark an organization as a lucrative target. Cybercriminals often share information about victims who have paid, increasing the likelihood of future attacks. Research indicates that companies which have paid once face significantly higher odds of being attacked again.

Given these risks, organizations are advised to invest in robust cybersecurity measures, including regular data backups, employee training, and incident response planning. Relying on ransom payments as a recovery strategy is not only ineffective but also perpetuates the cycle of cybercrime.