Ransomware Payments Rarely End the Threat, Survey Finds

A new survey from security firm Proofpoint is putting fresh numbers behind a warning that law enforcement has repeated for years: paying a ransomware gang rarely makes the problem go away. According to the research, 58 percent of surveyed businesses in the United Kingdom admitted to paying a ransom following a ransomware attack. But the data suggests that decision often invites more trouble rather than closure.

The survey found that roughly 22 percent of organizations that paid a ransom were extorted again by the same attackers, sometimes for additional payments tied to the same stolen data. In some cases, victims paid once to unlock their systems only to be contacted weeks or months later with fresh threats to leak the same information unless another payment was made. Even more concerning, about 2 percent of victims who paid a ransom never recovered their files at all, either because the decryption tools provided by attackers failed or because the criminals simply never intended to deliver on their promise.

This pattern lines up with what the FBI and Europol have been telling businesses for years: ransom payments fund criminal operations, rarely guarantee a clean resolution, and can mark an organization as a soft target willing to pay again.

Why Ransom Payments Invite Repeat Attacks

The logic behind repeat extortion is straightforward from a criminal's perspective. Once a business has demonstrated it will pay to make a problem disappear, that business becomes a known quantity to attackers, and often to other criminal groups who buy and sell victim data on underground forums. Paying a ransom does not necessarily mean stolen data is deleted. In many cases, copies remain on attacker infrastructure, get shared with affiliate groups, or are quietly kept as leverage for a second round of demands.

This is the core tension Proofpoint's data highlights: the short-term relief of paying to restore operations can create a longer-term liability. Attackers know that a company under pressure to resume business, protect customer trust, and avoid regulatory scrutiny is more likely to pay again than to walk away and accept the fallout of a data leak. That calculation is exactly what fuels re-extortion, and it is why security researchers continue to describe ransomware payment as a decision that trades an immediate crisis for a potentially larger, recurring one. Coverage of this same Proofpoint survey on repeat ransomware attacks noted that the incentive structure for attackers only strengthens once a victim proves willing to pay.

The Privacy Fallout Beyond the Ransom

While ransomware coverage often focuses on operational downtime, the privacy implications deserve equal attention. When a company pays a ransom to prevent data exposure, it is effectively trusting a criminal enterprise to honor a promise with no legal enforceability. Customer records, employee data, financial details, and health information can remain exposed to resale or leak regardless of payment. For the people whose data sits inside these breached systems, a ransom payment offers no real assurance that their personal information is safe.

This is particularly relevant for organizations handling sensitive personal data, where a breach can trigger notification obligations, regulatory penalties, and lasting reputational damage well after any ransom has been paid. The survey's findings reinforce that ransomware is not just an IT incident. It is a privacy incident with consequences that can resurface long after the initial headlines fade.

What This Means For You

If you run a business, or manage IT and security decisions for one, the takeaway from this survey is clear: paying a ransom is not a guaranteed path to resolution, and it may increase your exposure to future attacks. Decisions made in the panic of an active incident should be weighed against the reality that attackers often keep stolen data regardless of payment, and that visible willingness to pay can make an organization a repeat target.

For everyday consumers, this is a reminder that data breaches tied to ransomware attacks can have a longer tail than initial news coverage suggests. Personal information exposed in one incident may resurface in later leaks, even if the affected company reported the situation as resolved.

Key Takeaways

  • Nearly six in ten surveyed UK organizations paid a ransom after an attack, according to Proofpoint's data.
  • About 22 percent of those who paid were extorted again, often using the same stolen data.
  • A small percentage of victims who paid never regained access to their files at all.
  • Law enforcement agencies including the FBI and Europol continue to recommend against paying ransomware demands.
  • Businesses should invest in incident response planning, offline backups, and breach notification readiness rather than treating ransom payment as a quick fix.

Ransomware remains a persistent threat, but this survey adds weight to a message security professionals have pushed for years: paying does not buy peace of mind. Organizations and individuals alike are better served by prevention, preparation, and skepticism toward any promise made by criminal actors holding stolen data hostage.