Paying a cyber-criminal’s ransom is highly likely to trigger a second extortion attempt against your organisation, according to a landmark global study published by cybersecurity giant Proofpoint on Wednesday. The report warns that negotiating with digital extortionists is futile, as hackers increasingly exploit stolen data multiple times rather than honouring pay-off agreements.
The Proofpoint Findings: Double Extortion on the Rise
A comprehensive survey of 953 global organisations by cybersecurity firm Proofpoint found that more than one-third of companies that capitulated to a hacker’s ransom demands were subsequently targeted with a second extortion attempt. These findings validate a long-held warning from network defenders and security researchers: it is impossible to negotiate in good faith with cyber-criminals, as they have zero incentive to destroy stolen assets or walk away from a lucrative target.
From Single Payments to Multi-Stage Blackmail
Modern ransomware attacks are no longer simple, one-off financial transactions. Proofpoint’s data reveals that extortion tactics have evolved into sophisticated, multi-layered operations. Instead of merely locking systems and releasing them upon payment, attackers now routinely retain copies of sensitive corporate data, using the threat of public exposure as continuous leverage to squeeze victims for further payouts.
Although cyber-criminals frequently promise to delete or destroy stolen files once their initial demands are met, historical evidence proves these assurances are entirely worthless.
Real-World Fallout: Broken Promises and Double Payouts
Recent high-profile breaches illustrate the severe risks of trusting hacker guarantees. Last month, a cyber-attack at market research firm Klue exposed sensitive data belonging to its clients, which included several prominent cybersecurity companies. Despite striking a deal with the attackers—who claimed they had deleted the stolen information—Klue was later forced to admit that a separate hacking collective had obtained a sample of the compromised data, leaving clients exposed to ongoing extortion threats.
A similar crisis unfolded at Change Healthcare in 2024, when a Russian-speaking ransomware syndicate stole the private medical records of approximately 192 million people—representing the majority of the US population. Following a bitter dispute between the primary ransomware group and their affiliates, who frequently subcontract out specific phases of an attack, Change Healthcare was forced to pay separate ransoms to both criminal factions in a desperate bid to prevent the sensitive medical data from being leaked online.
Law Enforcement Confirms: Hackers Keep Your Data anyway
For years, cybersecurity specialists have suspected that ransomware syndicates quietly retain stolen databases long after receiving payment. This suspicion was officially confirmed in 2024 during a major international law enforcement operation led by UK police against the notorious LockBit ransomware gang. Following the seizure of LockBit’s infrastructure, authorities discovered vast troves of victim data still stored on the gang’s servers, years after those organisations had paid the demanded ransoms to have the files deleted.
