Fresh research out of Singapore is delivering an uncomfortable reminder to businesses weighing whether to pay a ransomware demand: the payment often doesn't end the ordeal. According to reporting from Singapore Business Review, 50% of local organisations hit by extortion attacks handed over money to their attackers, and a striking share of those ransomware victims who paid found themselves facing a second demand afterward.

The finding cuts against a common assumption that paying a ransom is a quick way to make a costly problem disappear. For many organisations, it appears to do the opposite: it signals to criminal groups that the victim is both willing and able to pay, making them a prime candidate for round two.

What the Research Found

The core figure from the study is simple but sobering. Half of the Singapore organisations surveyed that experienced a ransomware or extortion attack chose to pay their attackers. That's a coin-flip decision being made under enormous pressure, often with encrypted systems, halted operations, and looming reputational damage all weighing on the outcome.

What makes this data set particularly notable is the follow-up: a significant portion of those who paid didn't get closure. Instead, they received a second extortion demand, whether from the same group returning for more or a related actor exploiting the same access or leaked data. This pattern isn't unique to Singapore. Similar findings have surfaced elsewhere, including analysis showing that ransomware gangs re-extort 22% of victims who already paid, and separate research out of New Zealand found that roughly 1 in 5 ransom payments were betrayed by attackers who came back for more despite receiving payment.

Together, these data points paint a consistent picture across different markets: paying a ransom does not reliably purchase safety, and in a meaningful number of cases it may increase the odds of being targeted again.

Why Attackers Come Back for More

The behavioral logic here is straightforward once you consider it from the criminal's perspective. A victim who has already paid has demonstrated three things valuable to an extortionist: they have money available, they have decided that paying is preferable to the alternative, and they may lack the technical defenses to prevent a repeat intrusion.

Ransomware operations increasingly resemble businesses with their own internal metrics. A paying customer, in blunt terms, is a proven lead. Some groups also operate as affiliates or franchises, meaning a victim's data or network access can be resold or reused by a different criminal outfit entirely, resulting in a second demand that has nothing to do with the group behind the first attack. Either way, the victim is left holding the risk twice over.

This dynamic is exactly why cybersecurity agencies and researchers have long cautioned against treating ransom payment as a resolution rather than a temporary and unreliable stopgap.

Beyond Ransom Payments: Building Real Defenses

If payment isn't a guaranteed fix, where should organisations and individuals focus their energy instead? The answer lies in reducing the odds of a successful attack in the first place, and limiting the damage when one does occur.

That starts with the basics: maintaining offline, tested backups so encrypted data can be restored without negotiating with attackers. It also means tightening remote access controls, since compromised credentials and exposed remote desktop protocols remain common entry points for ransomware crews. Encrypting sensitive traffic and using secure, well-configured VPN connections for remote and hybrid work can reduce the attack surface that criminals rely on to gain an initial foothold. Employee training to spot phishing attempts, which remain a leading delivery method for ransomware payloads, rounds out a layered defense strategy that doesn't depend on hoping attackers keep their word.

What This Means For You

For small and mid-sized businesses in particular, this research should reshape incident response planning. If your organisation is ever hit by ransomware, the decision to pay shouldn't be treated as a clean exit strategy. Budget and plan as though payment might only buy temporary relief, not permanent resolution. That means having a documented incident response plan, legal and regulatory guidance ready in advance, and a clear-eyed understanding that paying may invite further targeting rather than end it.

For individuals and remote workers, the takeaway is more personal: the weak points attackers exploit, from unpatched software to unsecured connections, are often preventable with basic hygiene rather than expensive tools.

Key Takeaways

  • Half of Singapore organisations hit by extortion attacks paid their attackers, per the new research.
  • A notable share of ransomware victims who paid still received a second extortion demand, echoing similar findings globally.
  • Payment should be treated as a last resort and not a guaranteed solution to an active attack.
  • Strong backups, secure remote access, and phishing awareness reduce the odds of ever facing that decision at all.
  • Organisations should plan incident response assuming attackers may return, rather than assuming payment ends the threat.

Ultimately, the research is a call to shift focus from reactive payment decisions to proactive prevention. The businesses best positioned to weather a ransomware attack are the ones that never have to decide whether paying is worth the risk.