Companies Keep Paying Ransoms, New Data Shows
Despite years of guidance urging organizations to refuse ransomware demands, many companies are still cutting checks to cyber criminals. A new study from security firm Proofpoint found that nearly one-quarter (22%) of companies that paid a ransom were hit again with a second extortion demand, a figure that raises serious questions about whether paying actually solves anything.
The research lands at a moment when authorities are pushing harder than ever for organizations to hold the line against attackers. The UK's National Cyber Security Centre (NCSC) has long advised against paying ransoms, warning that it encourages further attacks and offers no guarantee that stolen or encrypted data will actually be returned. Yet the Proofpoint findings suggest that official advice and real-world business decisions are often two very different things.
Why Businesses Pay Anyway
Ransomware attacks put companies in an unenviable position. When systems are locked down or sensitive data is threatened with public exposure, executives are often forced to weigh reputational damage, regulatory exposure, and operational downtime against the cost of a ransom payment. For many organizations, paying can feel like the fastest way back to normal, even when security experts warn it rarely works out that cleanly.
That calculation becomes even more fraught given how the ransomware business itself has professionalized. Negotiation has become something of a cottage industry, with firms hired specifically to communicate with attackers and try to reduce demands. But that industry has not been without controversy. In one notable case, a professional negotiator was sentenced to 70 months in prison for his role in a BlackCat ransomware deal, a stark reminder that the people brokering these payments are not always operating in a company's best interest. A related case involving the same negotiator, identified as Martino in court records, further underscores how murky and legally risky the ransom payment ecosystem can become once a middleman is involved.
The Privacy Cost of Paying Up
The 22% repeat-extortion statistic is significant because it cuts against the core justification most companies give for paying: that it makes the problem go away. If nearly a quarter of victims are targeted again after paying, the payment is not buying safety. It may simply be confirming to attackers that the organization is willing and able to pay, making it a more attractive target for future attacks.
There is also a privacy dimension that often gets overlooked in these discussions. Ransomware attacks frequently involve the theft of sensitive data, customer records, employee information, financial details, well before any encryption occurs. Paying a ransom does not undo that exposure. Attackers may have already copied the data, and a payment offers no verifiable guarantee it will be deleted rather than sold or leaked later. For the individuals whose data sits inside a breached company's systems, the ransom negotiation happening behind closed doors has little bearing on whether their information stays private.
What This Means For You
If you're a consumer, this data is a reminder that a company's decision to pay a ransom does not necessarily protect your personal information. Breach notifications and credit monitoring offers following a ransomware incident are worth taking seriously, regardless of whether the affected company says it resolved the situation with attackers.
If you work in IT, security, or executive leadership, the Proofpoint findings should factor directly into incident response planning. Payment should never be treated as a quick fix. Organizations that have paid once appear to remain attractive targets, which means recovery plans need to include stronger post-incident hardening, not just a wire transfer and a sigh of relief.
Actionable Takeaways
A few practical steps can help reduce both the likelihood of an attack and the fallout if one occurs:
- Maintain offline, tested backups so encryption demands lose their leverage.
- Treat any ransomware incident as a data breach by default, since attackers frequently exfiltrate data before encrypting it.
- Consult law enforcement and agencies like the NCSC early, rather than jumping straight to payment or negotiation.
- If a negotiator is involved, vet them carefully given the legal risks highlighted by recent prosecutions.
- Communicate transparently with affected customers or employees regardless of whether a ransom was paid.
Ransomware isn't going away, and the temptation to pay for a quick resolution will remain strong. But this new data adds weight to what regulators have been saying for years: paying a ransom is rarely the end of the story, and it may just be the beginning of a second one.




