What Proofpoint's Study Found About Repeat Attacks

A new study from cybersecurity firm Proofpoint delivers a sobering reality check to organizations that treat ransomware payments as a quick fix. According to the research, over one-third of companies that paid a ransomware demand were later targeted by a secondary extortion attempt. In other words, writing the check doesn't close the book on an incident; for a significant share of victims, it simply opens a new chapter.

This finding matters because it challenges a common assumption inside boardrooms during a crisis: that paying attackers is the fastest way to make the problem disappear. Proofpoint's data suggests the opposite. Once a company demonstrates it's willing to pay, it can become a repeat target, either for the original attacker or for a different group that has learned the organization is a soft touch.

Why Paying Ransom Doesn't Guarantee Data Safety

The core issue highlighted by Proofpoint is that ransom negotiations are built on trust with criminals who have no binding obligation to honor their side of the deal. Paying to unlock encrypted files does not guarantee that stolen data hasn't already been copied elsewhere, nor does it prevent attackers from reselling access credentials, network maps, or exfiltrated files to other criminal groups.

This is the mechanism behind the repeat extortion cycle the study describes. Modern ransomware operations increasingly rely on double extortion, encrypting systems while also stealing sensitive data before demanding payment. Even if a decryption key is delivered as promised, the stolen data itself remains a liability. It can be used for a second shakedown, sold on criminal marketplaces, or leveraged by an entirely different threat actor who purchases access from the original attacker. The payment resolves the immediate outage, but it does nothing to address the underlying exposure of the organization's data.

The Growing Threat to Small and Mid-Sized Businesses

While large enterprises have historically dominated ransomware headlines, smaller and mid-sized businesses are increasingly in the crosshairs, often because they have fewer resources to invest in detection, response, and recovery. These organizations can be especially vulnerable to the repeat extortion pattern Proofpoint describes, since a single successful payment can flag them as both willing and able to pay again.

This dynamic is already playing out with ransomware-as-a-service operations that specifically target smaller organizations. As detailed in coverage of Qilin and The Gentlemen ransomware gangs escalating SMB attacks, these groups are competing for dominance by focusing on businesses that may lack the negotiation experience, legal counsel, or incident response infrastructure that larger companies can bring to bear. When a smaller company pays once, it may not have the resources to fundamentally change its security posture afterward, leaving the same vulnerabilities open for the next attempt.

Reducing Your Risk: Backups, Encryption, and Incident Planning

Proofpoint's findings reinforce a message that security professionals have been repeating for years: prevention and preparation matter more than negotiation. A few practical steps can meaningfully reduce both the likelihood of an attack and the damage if one occurs.

First, maintain offline or immutable backups that are tested regularly. A ransomware payment often becomes the only option when backups are missing, outdated, or themselves encrypted during the attack. Second, encrypt sensitive data at rest and in transit so that even if attackers exfiltrate files, the stolen data has limited value. Third, build an incident response plan before an attack happens, not during one. This plan should include clear roles, communication protocols, and pre-vetted legal and forensic contacts, so decisions aren't made under panic and time pressure.

Organizations should also assume that any data touched by an intrusion could eventually surface publicly or be resold, regardless of whether a ransom is paid. Planning for that possibility, through customer notification procedures, credit monitoring offers, and legal review, is far more reliable than hoping a criminal group will delete stolen files after payment.

What This Means For You

If your organization is ever faced with a ransomware demand, Proofpoint's research suggests the decision to pay should not be treated as a guaranteed resolution. The ransomware repeat extortion payment risk is real and documented: paying can mark you as a target rather than closing the incident. Whether you run a small business or manage security for a larger company, the safest assumption is that any ransomware event may not be a one-time occurrence unless you address the root causes that allowed the intrusion in the first place.

Key Takeaways

  • Don't assume payment ends the threat. Proofpoint found over a third of paying victims face a second extortion attempt.
  • Prioritize immutable, tested backups so payment is never your only path to recovery.
  • Encrypt sensitive data to limit the damage of exfiltration even if systems are compromised.
  • Build and rehearse an incident response plan before an attack, not during one.
  • Recognize that smaller businesses are increasingly targeted by groups like Qilin and The Gentlemen, making proactive defense essential regardless of company size.