What the New Ransomware Payment Data Shows

A new report from security firm Proofpoint, published Wednesday, delivers an uncomfortable confirmation for anyone who has ever considered paying a ransomware gang to make a problem go away: a significant share of victims who pay end up facing a second extortion demand. The report reinforces something security researchers and incident responders have argued for years, that ransomware negotiations are not conducted in good faith, and that paying does not guarantee an attacker will actually walk away.

Proofpoint's data adds hard numbers to a pattern defenders have long suspected anecdotally. Organizations that comply with a ransom demand are not buying closure. They're often buying a second round of leverage for the same attacker, or for a different group entirely, to come back and ask for more.

Why Paying a Ransom Invites a Second Attack

The logic behind repeat extortion is straightforward once you think about it from the attacker's perspective. A ransomware group's entire business model depends on victims believing that payment ends the crisis. But there's no legal contract, no enforcement mechanism, and no reputational risk strong enough to guarantee an attacker's word once the money has moved. If a victim has already demonstrated willingness and ability to pay, that victim becomes a more attractive target, not a settled account.

This is part of why security researchers describe ransomware negotiation as fundamentally different from a normal business transaction. There's no incentive for the other side to actually walk away. A criminal group that successfully extracted a payment once has every reason to test whether the same organization will pay again, whether by re-encrypting systems, threatening to leak previously stolen data a second time, or simply reopening a new demand tied to the original breach.

This dynamic is closely related to what the industry calls double extortion or multi-extortion, where attackers don't just encrypt files but also steal data beforehand, giving them multiple pressure points to squeeze a victim even after a ransom is paid. Proofpoint's findings suggest that even after that initial pressure campaign succeeds, the well doesn't necessarily run dry.

How Undetected Breaches Make Re-Extortion Easier

One reason repeat extortion works so well for attackers is that many victims don't fully understand the scope of a breach by the time they decide to pay. If an organization discovers encrypted files and negotiates a ransom without first identifying exactly what data was accessed, copied, or left behind as a backdoor, it has effectively agreed to a price without knowing what it's actually buying back.

This gap between detection and response is a recurring theme in ransomware research. As covered in a related report on ransomware detection failures, nearly half of all ransomware victims lose data before they even realize an attack is underway. That delay matters enormously here: if a victim doesn't know an attacker exfiltrated data weeks before deploying ransomware, paying to unlock files does nothing to address the stolen information sitting on a criminal server, which can be monetized again through a second demand, sold separately, or used for a fresh leak threat down the line.

Defensive Steps: Backups, Monitoring, and Incident Response Planning

The practical takeaway from Proofpoint's report isn't that ransom payment should never happen under any circumstances. It's that payment should never be treated as a guaranteed resolution. Organizations, and individuals managing smaller networks or businesses, are better served by investing upstream in prevention and detection rather than downstream in negotiation.

That means maintaining regular, tested, offline backups so encrypted files can be restored without paying anyone. It means investing in monitoring tools that can catch unauthorized data access before attackers have time to exfiltrate large volumes of sensitive information. And it means having an incident response plan in place before an attack happens, one that includes forensic investigation to determine exactly what was accessed, not just whether files were encrypted.

What This Means For You

For small business owners and individuals, the message from this research is clear: don't assume paying a ransom is the fast, clean solution it appears to be in the moment. Attackers who have already proven willing to extort you once have both the means and the motive to do it again. The real defense against ransomware repeat extortion attacks isn't a better negotiation strategy, it's reducing the odds you're in that position in the first place through strong backups, faster detection, and a clear response plan.

Actionable Takeaways

  • Treat ransom payment as a last resort, not a guaranteed fix, since Proofpoint's data shows attackers frequently return with new demands.
  • Prioritize offline, tested backups so encryption alone can't force a payment decision.
  • Invest in detection tools that catch data exfiltration early, since delayed detection gives attackers more leverage for repeat extortion.
  • Build an incident response plan before an attack occurs, including forensic steps to determine the full scope of any breach.
  • Assume that any data stolen before a ransom is paid remains a future risk, regardless of what attackers promise.