Proofpoint report: paying ransoms increases risk of repeat extortion
New data from Proofpoint reinforces warnings from governments and security researchers that paying hackers funds further criminal activity and fails to guarantee data deletion.

A report published by cybersecurity firm Proofpoint indicates that more than one-third of companies paying hacker ransoms face a second extortion demand. The findings, drawn from a survey of 953 companies, reinforce longstanding warnings from governments and security researchers that paying ransoms funds further criminal activity and fails to guarantee data deletion.
The data highlights an evolution in ransomware tactics, shifting from single-transaction payments to multi-leverage extortion models. According to Proofpoint, attackers increasingly retain stolen information to leverage future payments, contrary to their claims that data will be deleted after a settlement is reached.
Historical incidents have demonstrated that victims' data often remains on criminal servers despite payment agreements. During the LockBit takedown in 2024, U.K. law enforcement confirmed that victims' stolen data was stored on the gang's servers long after ransoms were paid. Similarly, the Change Healthcare breach in 2024 saw the company pay separate ransoms to different groups to prevent the release of 192 million people's medical data.
The complexity of these threats was further illustrated by the Klue hack reported last month. The market research firm struck a deal with hackers who claimed to have deleted the data, yet a separate group later stole sample data, exposing customers to potential future extortion demands.
Security researchers have long held that negotiating in good faith with extortion rackets is impossible due to the lack of incentive for criminals to walk away. Proofpoint's latest findings confirm that the landscape has moved beyond simple one-off payments, with attackers using retained data as a persistent threat for future leverage.
