Bad news — paying a ransomware demand might cause hackers to come back and ask for more
(Image credit: Getty Images)
- Proofpoint 2026 AI‑Era Ransomware Report found 54% of victims paid attackers despite warnings
- 37% faced repeat extortion after paying; 2% paid but never regained access to files
- Experts urge prevention: phishing awareness, offline backups, and AI‑powered endpoint protection
Security researchers Proofpoint have seemingly proved once again that paying ransomware actors does not guarantee they’ll walk away for good - in fact, they’ve proven that in many cases, they’ll simply come back for more because they know they can get paid.
The company's “2026 AI-Era Ransomware Report”, based on a survey of almost 1,000 security professionals across 12 markets, found globally, more than half (54%) of affected organizations paid their attackers to regain access to locked files and prevent them from sharing stolen documents on the dark web.
This is despite repeated pleas by law enforcement and the cybersecurity industry not to engage with the attackers and not to, under any circumstances, pay the ransom demand. Proofpoint argues that the real-world pressure organizations suffer when faced with disruptions is, in many instances, simply too big to tolerate.
Asking for a second payment
The logic behind the “don’t pay” argument is simple - by paying, the victims are motivating the attackers to do more damage, and are funding future attacks. At the same time, there is no guarantee that the decryption keys will work, that the attackers will really delete the files they had stolen, and that they won’t strike again in a few weeks.
This final argument has now been proven. While around half (56%) of victims paid one ransom and regained access, more than a third (37%) faced a second extortion demand soon after paying. Another 2% paid and never regained access at all.
Instead of paying the ransom demand, the industry suggests businesses protect their premises by educating their employees on the dangers of phishing, keeping updated backups in offline storage, and running (if possible, AI-powered) endpoint detection and protection services across the entire tech stack.
Via TechCrunch
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)