Why 1 in 5 Ransomware Payments Still Ends in Betrayal
New Zealand businesses weighing whether to pay a ransomware demand just got a sobering data point. According to reporting on which New Zealand companies are most likely to be targeted by ransomware hackers, 80% of victims who paid received a working decryption key and did not have their stolen data leaked as promised. That sounds reassuring until you flip the number around: in one out of every five cases, victims paid and got nothing. No key, no deleted files, no honored deal.
This is the uncomfortable core of ransomware ransom payment risks. The entire extortion model depends on victims believing that criminals will keep their word, because a reputation for reliability keeps future victims paying. But reputation among criminal groups is not a legal contract, and the reporting makes clear that some operators simply take the money and walk away, or worse, come back for more.
How Ransomware Groups Target and Re-Extort Victims
One of the more troubling details in the report involves a group called SpaceBears, which reportedly re-extorted victims who had already paid a ransom once. Instead of treating a payment as the end of an incident, these victims found themselves back at square one, facing a second demand for the same stolen data. This tactic undermines the basic premise that paying resolves the problem. If a criminal group has your data, a single payment does not guarantee it disappears from their possession or from the possession of anyone they later sell it to.
Ransomware groups tend to focus on organizations they believe are more likely to pay quickly, often because the cost of downtime or reputational damage outweighs the ransom itself. Recovery costs after an attack are consistently high, covering forensic investigation, system rebuilding, legal consultation, and potential regulatory reporting obligations. That financial pressure is exactly what attackers count on when they set their price and their deadline.
Reducing Exposure: Data Protection and Security Hygiene Basics
Given that even a successful payment carries roughly a 20% chance of failure, and that some groups may exploit victims twice, the more durable strategy is reducing the odds of a successful attack in the first place. This starts with basic but often neglected security hygiene: regular offline or immutable backups that ransomware cannot reach, timely patching of known vulnerabilities, multi-factor authentication on all remote access points, and network segmentation so a single compromised account cannot cascade into a full-scale encryption event.
Data minimization matters just as much as technical defenses. Organizations that store less sensitive data, retain it for shorter periods, and encrypt what they keep give attackers less leverage even if a breach occurs. This is also where understanding VPN jurisdiction becomes relevant for businesses and individuals handling sensitive traffic. The country where a service provider is legally based determines what data it can be compelled to hand over and what legal recourse victims have if something goes wrong. Choosing tools and vendors with clear, favorable jurisdictional standing is part of a broader defense posture, not a separate concern from ransomware prevention.
Broader digital policy conversations in New Zealand also intersect with this issue. As discussions around New Zealand's age verification plans show, the country is actively debating how much personal data platforms and regulators should collect and retain. Every new pool of stored personal information is a potential ransomware target, which makes data minimization a public policy question as well as a corporate one.
What This Means for Businesses and Everyday Users
For New Zealand businesses, the takeaway is not that paying a ransom is always pointless. The 80% figure shows attackers often do deliver. But treating payment as a reliable insurance policy is a mistake the data does not support. A one-in-five failure rate, combined with documented cases of repeat extortion, means payment should be a last resort weighed against legal, financial, and reputational factors, not a default response baked into an incident response plan.
For everyday users, the lesson is similar at a smaller scale. Personal backups, unique passwords, and cautious handling of email attachments and links remain the cheapest and most effective defenses against the ransomware that eventually finds its way to individuals through phishing campaigns. Recovery after the fact, whether you are a large company or a home user, is expensive and uncertain compared to prevention.
Key Takeaways
- Roughly 20% of ransomware victims who pay receive nothing in return, despite promises of decryption keys and data deletion.
- Some ransomware groups, including SpaceBears, have re-extorted victims who already paid once.
- Reliable offline backups and strong access controls reduce reliance on ransom payments entirely.
- Data minimization and provider jurisdiction awareness shrink the amount of leverage attackers can hold over you.
- Ransomware ransom payment risks should factor into every organization's incident response planning, not just the immediate cost of the demand.
Understanding ransomware ransom payment risks is ultimately about recognizing that prevention, backup discipline, and careful data handling offer more certainty than trusting a criminal enterprise to honor its side of an extortion deal.




