Greedy ransomware crews return for seconds after victims cough up first extortion payments

Jul 22, 2026 - 16:18
0 0
Greedy ransomware crews return for seconds after victims cough up first extortion payments

Security

Some never saw their files again either, infosec biz Proofpoint finds

Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn't mean the crooks leave you alone.

Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. Worse, 22 percent of those who pay get extorted again anyway. 

The UK broadly tracks the global picture: 54 percent of victim organizations paid, though the rate swings sharply by region, from just 19 percent in Japan to 93 percent in the US.

Cybersecurity biz Proofpoint, which published the data on Wednesday, attributes the regional variation to "a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation."

"But the core finding holds everywhere: ransomware creates enough pressure that a significant share of organizations in each of the surveyed markets choose to pay."

UK organizations that paid fared somewhat better than the 37 percent global average for repeat extortion. Still, the core lesson stands: paying doesn't reverse an attack. You can't trust a criminal's word. It just restarts a negotiation where the attacker holds every card, including the data, decryption keys, and the threat of publishing what they've stolen.

Operation Cronos, law enforcement's LockBit takedown, provided hard proof of what had long been suspected: cybercriminals often retain victim data even after being paid. Before Dmitry Khoroshev's cybercrime empire collapsed, this was an assumption, not evidence-based. 

Cronos didn't just shutter the then-leading ransomware gang; it undermined the entire premise that paying restores the status quo.

Proofpoint found that 2 percent of victims who paid a ransom never recovered their files at all. Earlier this year, Nitrogen's ESXi ransomware victims hit a similar wall after a coding error in the decryptor left some unable to fully restore access, and it was far from an isolated case.

Attackers don't need to hold up their end of the bargain to keep the payments coming. The better answer is to build cyber-resilience into the organization itself.

A word on AI

No 2026 security report is complete without AI. In the UK, 65 percent of surveyed security practitioners said AI had sharpened the attacks that precede ransomware and extortion, most notably malicious links, business email compromise, malicious attachments, and credential harvesting.

AI is not yet a key tool in ransomware payloads themselves, despite recent reports suggesting this may soon change. However, it is being used for more convincing phishing lures, sharper impersonation attempts, and faster system reconnaissance once attackers are inside a network. 

"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it," said Ryan Kalember, chief strategy officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale. 

"Organizations that continue treating ransomware as an endpoint or recovery problem are missing where these attacks most frequently begin: people, identities and trusted communications." ®

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User