Nearly Half Still Pay, But They're Haggling First

A new report making the rounds paints a familiar but uncomfortable picture: nearly half of organisations hit by ransomware encryption end up paying the ransom. The twist is that roughly half of those victims don't simply hand over the full amount demanded. Instead, they negotiate, often getting attackers to accept less than the original asking price before unlocking the encrypted files.

On the surface, that might sound like a small win for victims. Getting a criminal group to lower its price feels like a minor victory in an otherwise bad situation. But the bigger story here isn't about who's better at haggling. It's about what it means that ransom payment, and negotiating with criminals, has become a normalized part of how organisations respond to cyberattacks.

Why Companies Pay Instead of Walking Away

Ransomware works by encrypting an organisation's files and systems, making them unusable until a decryption key is provided, typically in exchange for payment. For companies without solid backups, or those facing pressure to restore operations quickly, paying can feel like the fastest way back to normal. That calculation gets even easier to justify when the attacker is willing to come down on price, which the report suggests happens often.

This negotiation dynamic isn't new to the ransomware economy. Many ransomware operations now run like businesses, complete with support chats, payment portals, and yes, room to negotiate. That professionalization is part of why paying has become such a common outcome rather than a last resort.

But paying doesn't guarantee a clean resolution. Even when a ransom is paid and a decryption key is handed over, there's no guarantee the attackers didn't already copy sensitive data before encrypting it. That's a critical detail often lost in conversations about ransom negotiations: the payment is usually about restoring access to files, not about undoing a breach that may have already happened.

The Privacy Risk Hiding Behind Every Ransom Payment

This is where the story connects to a much bigger privacy problem. Ransomware attacks increasingly involve data theft alongside encryption, meaning attackers exfiltrate copies of sensitive files before locking up the originals. Related reporting has found that 49% of ransomware victims lose data before detecting the attack, which means by the time a ransom demand even arrives, the damage to personal and organisational data may already be done.

That detail matters enormously for anyone whose personal information sits inside an organisation's systems, whether that's an employer, a healthcare provider, a school, or an online retailer. A successful negotiation on the ransom amount doesn't undo a data theft that already happened. It also doesn't stop attackers from selling or leaking that data later, regardless of whether the ransom was paid in full, negotiated down, or refused entirely.

Paying a ransom, even a reduced one, also risks reinforcing the business model itself. Every successful payment, negotiated or not, signals to attackers that ransomware remains profitable, which keeps the incentive structure intact for future attacks against other organisations.

What This Means For You

Most people reading about ransomware payment statistics aren't the ones deciding whether to pay. That decision usually falls to IT leadership, executives, or incident response teams. But the consequences ripple outward to employees, customers, and anyone whose data lives inside affected systems.

If you receive a breach notification from a company that experienced a ransomware attack, treat it seriously regardless of whether the news mentions a ransom being paid. Data theft can occur before encryption even begins, so a paid ransom and a restored system don't necessarily mean your information is safe. Watch for signs of identity theft, monitor your accounts, and consider credit monitoring if the organisation offers it following an incident.

For businesses and IT teams, the negotiation trend is a reminder that response planning needs to account for data exposure, not just system downtime. Backups help you avoid paying for a decryption key, but they don't prevent stolen data from being leaked or sold if attackers already exfiltrated it beforehand.

Actionable Takeaways

  • Don't assume a paid ransom means your data was never copied or exposed; ask affected organisations directly what was confirmed stolen.
  • Monitor accounts and credit activity after any breach notification, even if the company says the ransom was resolved.
  • If you run a business, prioritize early detection and network segmentation so attackers have less time to exfiltrate data before encryption hits.
  • Understand that ransom negotiation lowers cost, not risk; the exposure of stolen data remains a separate and lasting threat.

Ransomware payment trends will likely keep making headlines as more organisations weigh the cost of paying against the cost of rebuilding. But for everyday users, the real takeaway isn't about negotiation tactics. It's about staying alert to what happens to your data long after the headlines about a ransom payment fade.