Firms that pay ransoms face repeat extortion demands
A new study shows more than a third of companies that pay hacker ransoms are targeted again, demonstrating that paying up fails to resolve cyber crises and leaves firms exposed to ongoing financial risk.
Cybersecurity firm Proofpoint published a report on Wednesday showing that over a third of 953 surveyed companies that paid a hacker ransom were hit with a subsequent extortion demand. Governments have consistently warned against paying ransoms, but the new data quantifies the exact financial peril of complying with hackers. The findings confirm there is no good-faith negotiation to be had with an extortion racket.
For European businesses and investors, this represents a fundamental shift in cyber risk. Ransomware has evolved from a single-payoff transaction into a model of continuous leverage. Criminals now retain stolen data rather than destroying it, using the persistent threat of public leaks to demand further payments.
Hackers frequently promise to delete stolen files once a ransom is settled, but recent incidents prove otherwise. Last month, market research firm Klue paid a ransom to attackers who claimed to have deleted its data. A separate hacking group subsequently stole a sample of that same data, exposing Klue's customers to further extortion.
Corporate finances can be drained multiple times by the exact same breach. In 2024, Change Healthcare paid separate ransoms to a Russian-speaking gang and its own affiliates following a dispute between the criminal parties. The initial breach compromised the sensitive medical data of roughly 192 million people.
Law enforcement actions have validated these ongoing risks for European firms. During the 2024 takedown of the prolific LockBit ransomware gang, U.K. law enforcement confirmed that victims' stolen data remained stored on the group's servers long after ransoms had been paid. This proves that deleting data is a false promise, leaving companies that pay up vulnerable to future leaks.
The takeaway for corporate boards across Europe is stark. Negotiating with cybercriminals offers no guarantee of data recovery or confidentiality because the attackers have no incentive to walk away. Paying a ransom does not close a security vulnerability; it effectively marks a company as a reliable source of repeat revenue for criminal networks.