Paying Hackers’ Ransoms May Lead to More Extortion, Proofpoint Warns
A new Proofpoint report warns that companies paying ransomware demands often face additional extortion attempts, highlighting the growing risks of negotiating with cybercriminals.
Organisations that choose to pay hackers following a ransomware attack may still face additional extortion attempts, according to new research from cybersecurity company Proofpoint. The report reinforces long-standing advice from governments and security experts that paying a ransom does not guarantee stolen data will be deleted or that cybercriminals will stop targeting victims.
Proofpoint surveyed 953 organisations and found that more than one-third of companies that paid a hacker’s ransom later received a second demand for payment. The findings highlight how ransomware groups have increasingly shifted from one-time attacks to prolonged extortion campaigns using stolen data as continuing leverage against victims.
Ransomware tactics continue to evolve.
According to Proofpoint, modern ransomware attacks often involve stealing sensitive information before encrypting systems. Attackers then threaten to publish or sell that data unless victims continue making payments, leaving organisations vulnerable even after an initial ransom has been paid.
Security experts have long warned there is no reliable way to confirm that hackers delete stolen data after receiving payment, making negotiations with cybercriminals inherently risky.
High-profile breaches highlight the danger.r
The report references recent incidents that demonstrate the problem. Market research firm Klue said it reached an agreement with hackers after a cyberattack. Still, another criminal group later obtained a sample of the stolen data, exposing customers to possible future extortion.
Proofpoint also highlighted the 2024 Change Healthcare ransomware attack, in which sensitive medical information affecting around 192 million people was stolen. During a dispute between the attackers and affiliated criminal groups, the company made separate ransom payments in an effort to keep the data from being released.
Law enforcement backs the warning.
Evidence gathered during the 2024 international operation against the LockBit ransomware gang supported long-held concerns that victims’ stolen data was still stored on the group’s servers even after ransom payments had reportedly been made.
Proofpoint said the findings reinforce the importance of strong cybersecurity measures, secure backups and incident response planning, as paying a ransom may not prevent future extortion or ensure stolen information is permanently deleted.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0