Ransomware victims face repeat extortion after initial payment, Proofpoint study finds

Over a third of ransomware victims who pay are targeted again by the same or different crews, challenging the assumption that payment resolves the threat.

Abstract representation of cyclical ransomware attacks through repeating geometric patterns
AI-generated illustration · Sylvaris

Payment fails to guarantee resolution

Security firm Proofpoint reports that more than one-third of ransomware victims who pay extortion demands face subsequent attacks. The finding undermines the rationale organizations use to justify ransom payments as a quick resolution strategy.

Some victims never received decryption keys despite paying, while others were re-extorted by the same threat actor or targeted by different groups after initial payment. The data suggests payment creates a marker identifying organizations willing to negotiate under duress.

Multiple attack vectors for repeat targeting

Ransomware crews return for additional extortion using several methods. Some demand further payment for data deletion promises, while others exploit the same initial access vector that remained unpatched after the first incident.

Different threat groups also target organizations known to have paid previously. Information about payment willingness circulates within criminal ecosystems, making paid victims more attractive targets for subsequent campaigns.

Implications for incident response planning

The research challenges conventional cost-benefit analysis of ransom payment. Organizations that pay face not only immediate financial loss but elevated risk of repeat targeting, potentially resulting in higher total costs than initial recovery investment would require.

Security teams should plan for scenarios where payment does not resolve the incident or leads to subsequent attacks. Incident response plans that rely on payment as a recovery mechanism may need revision to account for repeat extortion risk and incomplete data recovery.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.