A Third of Ransom Payers Face Second Extortion Demand
New survey data confirms what incident responders have suspected for years: paying a ransomware gang rarely buys the closure victims think they're purchasing. According to a survey of 953 companies, more than one-third of organizations that paid a hacker's ransom were later hit with a second extortion demand. The finding adds hard numbers to a pattern security teams have watched play out again and again, where a single ransomware incident turns into a recurring liability rather than a one-time crisis.
The implications go beyond corporate balance sheets. Every time a company pays to make an extortion demand go away, it's implicitly signaling to attackers that its data, and the personal information of its customers and employees, is worth coming back for.
Why Paying Once Invites a Second Attack
Ransomware has evolved well past the days of a single encrypted hard drive and a Bitcoin wallet address. Modern attacks typically involve data theft before encryption even begins, meaning the criminals already have copies of sensitive files before they lock anything down. That shift is central to understanding why the second extortion demand has become so common.
Once attackers have exfiltrated data, they hold two separate points of leverage: the decryption key and the threat of publishing or selling stolen records. A company that pays for the first often finds itself negotiating over the second weeks or months later, sometimes from the same group and sometimes from an entirely different one that purchased or was tipped off about the stolen data. This finding lines up closely with the Proofpoint research showing 1 in 3 ransomware payers get hit again, and it echoes an earlier industry ransomware report finding 37% of payers face repeat demands. Multiple independent surveys landing in the same range suggests this isn't statistical noise. It's a structural feature of how ransomware economics work now.
There's also a simple incentive problem. A company that pays once has demonstrated it is willing and able to pay. That reputation can spread inside criminal networks, making a previously breached organization a more attractive repeat target than one that never engaged with attackers at all.
The Privacy Fallout for Customers and Employees
The repeat-extortion trend matters most to the people whose data sits inside these breached systems. Payroll records, health information, customer account details, and internal communications don't disappear once a ransom is paid. They often remain in the hands of criminals who have every reason to monetize them again, whether through a second ransom demand, a sale on dark web marketplaces, or use in follow-on scams like phishing and identity theft.
This pattern isn't limited to any one sector or region. Data theft has become a near-universal component of ransomware attacks, a trend also visible in reporting on India, where 71% of ransomware incidents involved data theft according to separate Proofpoint findings. The consistency across geographies reinforces that encryption is increasingly a secondary concern for attackers. The real prize is the data itself, and that data keeps generating value for criminals long after the initial headline fades.
What This Means For You
If you're a consumer, this survey is a reminder that a company's ransomware disclosure isn't necessarily the end of the story. Data stolen in an attack can resurface in later leaks, scams, or fraud attempts, sometimes long after the original incident was resolved and reported as closed.
If you run a business, or advise one on incident response, the takeaway is more direct: treating a ransom payment as a final fix is a mistake the data doesn't support. Any negotiation with attackers should be paired with a full forensic review of what was actually taken, not just what was encrypted, along with steps to secure or rotate credentials, monitor for renewed contact, and notify affected individuals promptly rather than waiting to see if a second demand arrives.
Key Takeaways
- More than a third of companies that pay a ransomware demand face a second extortion attempt, according to the 953-company survey.
- Data theft, not just encryption, is now standard in most ransomware attacks, giving criminals a second point of leverage even after a ransom is paid.
- Paying once can mark an organization as a reliable target, increasing the odds of repeat targeting.
- Consumers and employees whose data was involved in a breach should assume exposure may continue well after the incident is publicly resolved.
- Businesses should pair any ransom decision with a thorough audit of exfiltrated data and proactive notification, rather than assuming payment ends the threat.
Ransomware negotiations are messy and high-pressure, but the data is now clear on one point: a payment buys time, not certainty. Organizations and individuals alike are better served by planning for the possibility of a follow-up demand than by assuming the first one was the last.




