Proofpoint Survey: 33% of Ransomware Payers Hit With Second Extortion Demand

Key Points
- Proofpoint surveyed 953 companies and found 33% were hit with second extortion demands after paying initial ransoms.
- Hackers often retain stolen data even after payment, as confirmed by UK law enforcement during the 2024 LockBit takedown.
- Change Healthcare paid separate ransoms to multiple criminal groups in 2024 after a breach affecting 192 million Americans.
Hackers Retain Data Despite Payment Promises
One of the most damaging revelations from Proofpoint's research involves the fate of stolen data after ransom payments. Ransomware operators have repeatedly claimed they will delete or destroy victims' compromised data following payment, but past incidents demonstrate these assurances are unreliable.
Read Next

Meta Reports Q2 Earnings Amid AI Investment Concerns
7 days ago

Nvidia Launches Cybersecurity Initiative for Open-Source AI Defense
8 days ago
The Klue breach last month provides a concrete example. The market research firm struck a deal with hackers who claimed to have deleted stolen customer data. However, Klue later discovered that a separate hacking group had obtained a sample of the stolen data, leaving the company's cybersecurity firm customers exposed to potential future extortion attempts. This exposure demonstrates how initial payments do not prevent data from circulating to other criminal actors.
Change Healthcare faced an even more severe outcome following a 2024 breach. A Russian-speaking ransomware gang stole health and medical data belonging to approximately 192 million Americans—the majority of the country's population. When disputes emerged between the hackers and their criminal affiliates over payment splits, Change Healthcare ultimately paid ransoms to both groups of criminals to prevent the sensitive medical data from being released online.
Related coverage: Meta Reports Q2 Earnings Amid AI Investment Concerns
UK law enforcement provided direct confirmation of these practices during their 2024 takedown of the prolific LockBit ransomware gang. Police investigating the criminal operation discovered victims' stolen data stored on LockBit's servers long after those same victims had already paid demanded ransoms. This finding definitively proved that ransomware operators routinely retain victim data regardless of payment compliance.
The Proofpoint data shows that ransomware attacks have transformed from simple extortion schemes into sophisticated criminal enterprises that leverage multiple forms of pressure against victims. By retaining stolen data, maintaining backup copies, and sometimes selling that data to additional criminal groups, hackers create multiple revenue streams from a single breach while reducing incentives to actually conclude negotiations with victims.
Governments have warned against ransom payments for years, citing both the funding of criminal infrastructure and the perpetuation of ransomware-as-a-business models. Proofpoint's findings add a personal security dimension to these policy arguments: paying a ransom increases the statistical likelihood that a company will face extortion demands again from the same or related criminal groups.
Why this matters: If your organization has considered paying a ransomware demand to end a cyberattack, Proofpoint's data suggests a one-in-three chance you will face another extortion demand from the same attackers afterward. Even if you pay, hackers may retain your data indefinitely and sell it to rival criminal groups, meaning your second—and third—extortion threat may come from entirely different actors. This effectively multiplies both the financial cost and security risk of the initial decision to pay.
What This Means
Ransomware gangs will likely continue multi-stage extortion tactics as long as some companies pay initial demands. The prevalence of repeat extortion suggests criminals now budget for negotiation-resistant targets and backup revenue streams. Enterprise security spending on air-gapped backups and incident response may accelerate as organizations recognize that payment provides no guarantee of safety or data deletion.
Sources: AP, Reuters, ESPN, Bloomberg, BBC and other international news outlets.
Disclaimer: This article is for informational purposes only. Content is based on publicly available news sources.
NewsOracle Editorial
The NewsOracle Tech Desk covers breaking technology news including AI, Apple, Google, Tesla, Meta, OpenAI and product launches.
Latest coverage: Cybersecurity


