Future Tech & AI Wonders · Morgan Chen · 22 July 2026

If you pay a hacker's ransom, expect another demand

If you pay a hacker's ransom, expect another demand

If you pay a hacker's ransom once, attackers often return with another demand. Proofpoint surveyed 953 companies and found over one-third of those that paid faced a second extortion hit, reinforcing why governments warn that paying rarely ends the threat.

Key Takeaways

Why do attackers return after you pay a hacker's ransom?

Security researchers and network defenders have long argued that it is impossible to negotiate in good faith with an extortion racket. There is little incentive for criminals to walk away once a victim has shown they will pay.

Governments have warned not to pay ransom demands because doing so lets attackers profit and can fund the next campaign. A TechCrunch report on Proofpoint's findings adds another reason: many victims who pay are targeted again.

For more coverage of cybersecurity and emerging threats, explore BlasterPost's Future Tech & AI Wonders hub.

What did Proofpoint find about repeat ransom demands?

In a report published Wednesday, cybersecurity firm Proofpoint said it surveyed 953 companies. More than one-third of companies that paid a hacker's ransom were hit with a second extortion demand.

The data also shows how ransomware and extortion have changed. Attacks have moved beyond a single transaction in which hackers get paid once and move on. Many now use multiple forms of leverage, including retaining stolen data under the threat of publicly releasing it.

Does paying mean your stolen data will be deleted?

Hackers have claimed they will delete or destroy a victim's stolen data after payment. Past incidents suggest that often is not true.

Last month, a hack at market research firm Klue exposed data belonging to its customers, including several cybersecurity firms. Klue said it struck a deal with the hackers, who claimed to have deleted the data. The company later conceded that a separate hacking group obtained a sample of the stolen data, leaving customers exposed to potential future extortion.

In 2024, Change Healthcare faced a similar bind after a Russian-speaking ransomware gang stole the health and medical data of roughly 192 million people in America. Amid a dispute between the hackers and their affiliates, Change Healthcare paid separate ransoms to both groups to keep the data offline.

U.K. law enforcement later reinforced the pattern during 2024 takedown efforts against the LockBit ransomware gang. Police said they found victims' stolen data stored on LockBit's servers long after ransoms had been paid.

The takeaway for defenders is blunt: if you pay a hacker's ransom, you may still face repeat pressure, and payment does not guarantee that stolen data disappears.

← Open in blast feed