Paying the Ransom Doesn't Guarantee Anything

A new study covering Australia and New Zealand has put hard numbers behind something security professionals have warned about for years: paying a ransomware demand is a gamble, not a guarantee. According to reporting from Insurance Business, 34% of organizations in the region that suffered a ransomware attack chose to pay the ransom. Of those, 36% said the payment still failed to restore their data, either because the attackers withheld the decryption keys and access, or because they came back demanding more money later.

That's more than one in three payments producing no real recovery. For organizations weighing whether to pay, and for the customers, employees, and patients whose personal data sits inside those breached systems, this is a sobering reality check. Ransomware has never been a simple transaction, and this data confirms that even victims who comply with attacker demands are frequently left holding the bag anyway.

Why 'Just Pay It' Is the Wrong Question

The insurance industry angle here is telling. Brokers and insurers have traditionally framed the ransomware conversation around a binary choice: pay or don't pay. But the failure rate suggests that question misses the point entirely. Even a successful payment doesn't undo the fact that attackers already had access to sensitive systems, copied or exfiltrated data, and demonstrated they can return whenever they choose.

This mirrors a broader pattern the extortion economy has settled into. As we've covered in our look at why the extortion economy persists, ransomware groups have adapted their business models specifically because payment, however unreliable, remains common enough to sustain the industry. When more than a third of paid ransoms don't deliver working decryption or a clean exit, it suggests many criminal operations are either poorly organized, deliberately dishonest, or using the initial payment as a foothold for further extortion rather than a resolution.

For organizations building incident response plans, this data argues for a fundamental shift: the real question isn't "how do we recover everything after paying?" but "what can we recover regardless of whether we pay at all?" That reframes ransomware preparedness around resilience rather than negotiation.

Prevention Still Beats Negotiation

The most effective defense against a failed ransom payment is never needing to consider one. A few practical measures consistently reduce an attacker's leverage:

  • Offline and immutable backups. If data can be restored from backups that attackers never touched, the entire ransom conversation becomes optional rather than urgent.
  • Network segmentation. Limiting how far an intruder can move once inside a network reduces the blast radius of any single compromise, so attackers can't encrypt everything at once.
  • Encryption of sensitive data at rest. Even if attackers exfiltrate files, encrypted data is far less useful to them for secondary extortion or resale.
  • Multi-factor authentication and strong access controls. Many ransomware incidents start with a single compromised credential; MFA closes that door in a large share of cases.

None of these measures are exotic. They're standard practice recommendations that, according to this data, too many organizations still haven't fully implemented, given how many end up negotiating with attackers in the first place.

Reducing Exposure to Initial Compromise

Ransomware doesn't start with encryption. It starts with an initial breach, often through a phished credential, an exposed remote access point, or unpatched software. This is where network-level protections, including VPNs configured with strong authentication and limited access scopes, play a supporting role. A VPN alone won't stop ransomware, but it can reduce the attack surface by ensuring remote connections are encrypted and authenticated, making it harder for attackers to intercept credentials or exploit exposed services as an entry point.

What This Means For You

If you're an individual whose data sits with an organization that could be targeted, this study is a reminder that a ransomware attack rarely ends cleanly, even when the organization pays. Data that was exfiltrated before encryption can still leak or be sold regardless of any payment. If you're notified of a breach involving your information, treat it seriously: change reused passwords, watch for phishing attempts referencing the breach, and monitor accounts for unusual activity.

For businesses, the message is equally direct. A ransom payment is not a recovery plan, it's a last resort with a real chance of failure. Insurance can help offset financial losses, but no policy restores data that attackers never intended to return.

Actionable Takeaways

  • Assume any ransom payment has a meaningful chance of not working, and build recovery plans that don't depend on attacker cooperation.
  • Prioritize offline, tested backups over cyber insurance as your primary recovery strategy.
  • Segment networks and enforce MFA to limit how a single compromised account becomes a full-scale attack.
  • If you're notified your data was involved in a breach, act on that notice immediately rather than assuming a ransom payment resolved the issue.

Ransomware remains a persistent threat precisely because paying sometimes works, just not reliably enough to bet an organization's future on it. The safer path is reducing exposure before an attack happens, not negotiating after one succeeds.