Governments have long warned against accepting ransom demands from hackers, arguing that doing so would allow criminals to profit from cyberattacks and fund subsequent attacks. There's another reason. Once you pay, hackers are unlikely to leave you alone and many will come back and ask for additional fees.
In a report released Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that more than a third of those that paid a ransom to hackers were hit with a second extortion request. The findings underscore a long-standing understanding among security researchers and network defenders that it is impossible to negotiate in good faith with an extortionist because the other side has no incentive to actually walk away.
Proofpoint data shows that ransomware and extortion attacks have evolved from a single transaction in which hackers receive a payout and move on to the next, to a multi-vehicle effort, including holding stolen data under threat of publication.
Hackers have claimed in the past that they would delete or destroy victims' stolen data, but past incidents show this is not true.
Last month, market research firm Crew was hacked, exposing the data of its clients, including several cybersecurity firms. The company announced that it had reached an agreement with the hackers who claimed to have deleted the data, but later acknowledged that another group of hackers had swiped samples of the company's stolen data, exposing customers to potential future extortion claims.
A similar situation befell Change Healthcare in 2024 after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, approximately 192 million people. Amid a dispute between hackers and their affiliates (criminal groups often subcontract their attacks), Change Healthcare paid separate ransoms to both criminal groups to prevent sensitive medical data from being published on the internet.
Security researchers have long suspected that ransomware and extortion rings retain victims' stolen data even after payments have been made. British law enforcement confirmed this during a crackdown operation targeting the prolific ransomware group LockBit in 2024. Police announced that they discovered the victims' stolen data stored on LockBit's servers long after the victims had paid the ransom.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

