Ransomware victims face repeat extortion after initial payment, Proofpoint study finds
Over a third of ransomware victims who pay are targeted again by the same or different crews, challenging the assumption that payment resolves the threat.
Payment fails to guarantee resolution
Security firm Proofpoint reports that more than one-third of ransomware victims who pay extortion demands face subsequent attacks. The finding undermines the rationale organizations use to justify ransom payments as a quick resolution strategy.
Some victims never received decryption keys despite paying, while others were re-extorted by the same threat actor or targeted by different groups after initial payment. The data suggests payment creates a marker identifying organizations willing to negotiate under duress.
Multiple attack vectors for repeat targeting
Ransomware crews return for additional extortion using several methods. Some demand further payment for data deletion promises, while others exploit the same initial access vector that remained unpatched after the first incident.
Different threat groups also target organizations known to have paid previously. Information about payment willingness circulates within criminal ecosystems, making paid victims more attractive targets for subsequent campaigns.
Implications for incident response planning
The research challenges conventional cost-benefit analysis of ransom payment. Organizations that pay face not only immediate financial loss but elevated risk of repeat targeting, potentially resulting in higher total costs than initial recovery investment would require.
Security teams should plan for scenarios where payment does not resolve the incident or leads to subsequent attacks. Incident response plans that rely on payment as a recovery mechanism may need revision to account for repeat extortion risk and incomplete data recovery.