A Third of ANZ Organisations Still Choose to Pay

New research from Commvault has confirmed what many security professionals have long suspected: paying a ransomware demand is far from a reliable fix. The company's State of Data Resilience ANZ 2026 report found that 34% of organisations across Australia and New Zealand that experienced a ransomware attack went ahead and paid the ransom, despite having no real assurance that their data would be returned or their systems restored to working order.

The finding lands at a moment when ransomware has become less of a rare crisis event and more of an operational reality for businesses in the region. Yet the decision to pay is still, in many cases, being made under extreme pressure, in the middle of an active incident, rather than as part of a calm, pre-planned response strategy.

Why Paying Rarely Solves the Real Problem

The most important detail in Commvault's findings is not that organisations are paying, it's what happens after they do. Handing over a ransom does not automatically mean stolen or encrypted data comes back intact, or that the attacker deletes the copies they took before locking systems down. This distinction matters enormously from a privacy standpoint. Many ransomware incidents today involve data theft as well as encryption, meaning customer records, employee details, or financial information may have already left the organisation's network before any ransom conversation even begins.

A related survey covering the same region drives this point home. That research found that 36% of ransom payments fail to restore data, meaning more than a third of organisations that paid still ended up without their systems or files working properly. Paying, in other words, is not a transaction with a guaranteed outcome. It's a gamble made with an adversary who has no legal or reputational obligation to follow through.

For organisations holding sensitive personal data, whether that's health records, financial details, or customer identity information, this creates a compounding privacy risk. Even a successful payment doesn't undo the exposure that already occurred. Data that was copied by attackers before encryption can still be leaked, sold, or used for further extortion regardless of whether a ransom was paid. Commvault's research suggests that too many ANZ organisations are treating ransom payment as a recovery strategy, when it functions more like a bet placed after the damage is already done.

The Pressure to Decide in a Crisis

Part of what makes this pattern persistent is the environment in which these decisions get made. Ransomware attacks tend to escalate quickly, often locking staff out of critical systems within hours. Under that kind of pressure, with operations frozen and customers or partners asking questions, paying can feel like the fastest path back to normal. Commvault's report frames this as organisations making high-stakes ransomware decisions in the middle of a crisis, rather than as part of a tested, pre-existing plan.

That crisis-driven decision-making is precisely why preparation matters so much more than reaction. Organisations with tested backup systems, clear incident response plans, and pre-agreed criteria for whether to engage with attackers are in a far stronger position than those improvising in real time. The data suggests that many ANZ businesses have not yet reached that level of preparedness, and are instead defaulting to payment because it appears to be the only lever available in the moment.

What This Means For You

If you're a consumer, employee, or customer of any organisation, this research is a reminder that a ransomware payment by a company doesn't mean your data is safe. Even if a business announces it has resolved an incident, information that was exposed during the attack may still be circulating. It's worth paying attention to breach notifications from any service you use, and treating them seriously even if the organisation states that a ransom was paid or systems were restored.

If you work in a business, especially one handling customer or employee data, the takeaway is more direct: don't let a ransom payment decision be made for the first time during an actual attack. Organisations that plan ahead, test their backups, and have a clear response protocol are far less likely to face the kind of no-win scenario Commvault describes, where payment doesn't guarantee data return and privacy exposure has often already happened by the time the ransom note arrives.

Key Takeaways

  • Paying a ransomware demand does not guarantee your data or systems will be restored, and it does not undo any data theft that already occurred.
  • Data exposure and privacy risk can exist independently of whether a ransom is paid, since attackers often steal information before encrypting it.
  • Organisations should build ransomware response plans and test backups before an incident occurs, not during one.
  • Individuals should stay alert to breach notifications even when a company reports an incident as resolved.

Ransomware isn't going away, and Commvault's research makes clear that ANZ organisations are still navigating these decisions reactively rather than strategically. Building resilience before an attack happens remains the most reliable way to protect both business operations and the personal data organisations are trusted to safeguard.