Bad news — paying a ransomware demand might cause hackers to come back and ask for more

Security News

Bad news — paying a ransomware demand might cause hackers to come back and ask for more

Credit: The original article is published here.
  • Proofpoint 2026 AI‑Era Ransomware Report found 54% of victims paid attackers despite warnings
  • 37% faced repeat extortion after paying; 2% paid but never regained access to files
  • Experts urge prevention: phishing awareness, offline backups, and AI‑powered endpoint protection

Security researchers Proofpoint have seemingly proved once again that paying ransomware actors does not guarantee they’ll walk away for good – in fact, they’ve proven that in many cases, they’ll simply come back for more because they know they can get paid.

The company’s “2026 AI-Era Ransomware Report”, based on a survey of almost 1,000 security professionals across 12 markets, found globally, more than half (54%) of affected organizations paid their attackers to regain access to locked files and prevent them from sharing stolen documents on the dark web.

This is despite repeated pleas by law enforcement and the cybersecurity industry not to engage with the attackers and not to, under any circumstances, pay the ransom demand. Proofpoint argues that the real-world pressure organizations suffer when faced with disruptions is, in many instances, simply too big to tolerate.

Asking for a second payment

The logic behind the “don’t pay” argument is simple – by paying, the victims are motivating the attackers to do more damage, and are funding future attacks. At the same time, there is no guarantee that the decryption keys will work, that the attackers will really delete the files they had stolen, and that they won’t strike again in a few weeks.

This final argument has now been proven. While around half (56%) of victims paid one ransom and regained access, more than a third (37%) faced a second extortion demand soon after paying. Another 2% paid and never regained access at all.

Instead of paying the ransom demand, the industry suggests businesses protect their premises by educating their employees on the dangers of phishing, keeping updated backups in offline storage, and running (if possible, AI-powered) endpoint detection and protection services across the entire tech stack.

Via TechCrunch

Leave a Reply

Your email address will not be published. Required fields are marked *