AI Is Making Ransomware More Effective, Indian Organisations Say

A new industry report cited by Express Computer found that 62% of Indian organisations affected by ransomware believe artificial intelligence has made these attacks more effective. The finding lands at a moment when security teams across the country have spent years building up defenses, patching systems, training staff, and investing in detection tools, yet attackers appear to be adapting faster than expected.

The reason AI keeps coming up in ransomware conversations isn't mysterious. Tools that can automate reconnaissance, generate convincing phishing content, or help attackers move through a network more quickly reduce the time and skill needed to pull off a successful intrusion. For organisations trying to defend against ransomware, that shift matters because it changes the pace of the threat, not just its sophistication.

The Double Extortion Trap: When Paying Isn't the End

Perhaps the more consequential detail in the report isn't about AI at all. Among organisations that paid a ransom, nearly half (48%) reported facing a second extortion demand afterward. That statistic reframes what ransomware actually is in 2025. It's no longer a single transaction where a victim pays and the ordeal ends. Instead, it has become an ongoing negotiation in which attackers hold several forms of leverage simultaneously: continued encryption of systems, copies of stolen data, and the standing threat of releasing that data publicly.

This layered leverage is what security researchers often call double or triple extortion, and it explains why paying a ransom no longer guarantees resolution. Even after a payment clears, the stolen data still exists somewhere, and attackers retain the option to monetize it again, whether by demanding more money or simply selling it.

Why This Matters for Personal and Customer Privacy

The privacy implications here extend well beyond the breached organisation itself. When ransomware groups steal data before encrypting systems, the people whose information sits in those databases, customers, employees, patients, become collateral in a negotiation they have no part of. Recent incidents outside India illustrate how this plays out. In Europe, stolen customer records from telecom providers have shown up for sale on dark web forums, as seen when Iliad Italia customer data was listed for sale on the dark web, or claimed outright by extortion groups, as in the case where ShinyHunters claimed a breach at Odido affecting 21 million records.

Those cases also show how breach fallout can escalate over time. A single Odido incident, for instance, led to a data breach affecting 6.2 million records and later attracted a class-action response that gathered over 200,000 supporters within 24 hours. The pattern is consistent: once data leaves an organisation's control, it can resurface in lawsuits, dark web listings, or repeat extortion attempts long after the initial headline fades. The Indian findings suggest this same dynamic, a second extortion demand following a paid ransom, is becoming a defining feature of ransomware rather than an exception.

What This Means For You

If you're an employee, customer, or user whose data sits with an organisation that experiences a ransomware attack, the practical risk isn't limited to whether that company pays a ransom. It's whether your personal information was copied before encryption took place, and what happens to it afterward. Even organisations that respond quickly and pay to resolve an incident may still see that data circulate later.

For businesses, the takeaway from the AI angle is equally direct: faster, more automated attacks mean less time between initial compromise and full-scale impact. Assuming there's a predictable window to detect and stop an intrusion is increasingly risky.

Actionable Takeaways

For individuals: monitor accounts tied to services you use for unusual activity, use unique passwords across accounts, and pay attention to breach notifications rather than dismissing them as routine.

For organisations: assume that any ransomware incident may involve data theft, not just encryption, and build response plans around that assumption. Regularly test backup and recovery processes so paying a ransom is never the only option on the table, and treat AI-driven threats as a reason to speed up detection and response rather than a reason for alarm.

Ransomware's evolution into a multi-stage extortion process, accelerated by AI tools, means both defenders and the people whose data is at stake need to think beyond the moment of attack. Staying informed about how these incidents unfold, and what happens to stolen data afterward, remains one of the most effective ways to stay prepared.