Tech news in 3 minutes
If you pay a hacker’s ransom, chances are that they’ll come back for more
Proofpoint survey reveals that over one-third of companies paying ransomware demands face a second extortion, reinforcing why cybersecurity experts warn against negotiating with criminals. In a report published Wednesday, cybersecurity giant Proofpoint surveyed 953 companies and found that more than one-third of ransom payers were hit with additional extortion demands. The findings underscore the long-held understanding among security researchers that paying a hacker’s ransom funds future attacks and provides no guarantee of leaving victims alone. Proofpoint’s data shows ransomware and extortion attacks have evolved from a single transaction into a multi-leverage scheme, where hackers retain stolen data under threat of public release. Despite past promises by hackers to delete data, incidents prove otherwise. Last month, market research firm Klue struck a deal with hackers who claimed to have deleted stolen data, but a separate hacking group later swiped a sample, leaving customers exposed to potential future extortion. In 2024, Change Healthcare paid separate ransoms to two criminal groups after a Russian-speaking ransomware gang stole health data of 192 million Americans, amid a dispute between hackers and their affiliates. U.K. law enforcement confirmed during takedown efforts against the LockBit ransomware gang in 2024 that victims’ stolen data remained on LockBit’s servers long after payment. The Proofpoint report reinforces that it is impossible to negotiate in good faith with an extortion racket, as there is no incentive for criminals to walk away. The findings highlight the critical need for robust cybersecurity defenses and incident response plans that avoid ransom payment altogether.