If you pay a hacker’s ransom, chances are that they’ll come back for more
Over one-third of companies that paid ransoms faced subsequent extortion demands, proving payment does not guarantee safety. Ransomware tactics have evolved from single transactions to multi-leverage extortion involving retained stolen data. Law enforcement takedowns confirm hackers retain victim data on servers even after ransom payments are made. Industry incidents like Klue and Change Healthcare demonstrate that paying multiple groups or trusting deletion claims is ineffective.
Analysis
TL;DR
- Over one-third of companies that paid ransoms faced subsequent extortion demands, proving payment does not guarantee safety.
- Ransomware tactics have evolved from single transactions to multi-leverage extortion involving retained stolen data.
- Law enforcement takedowns confirm hackers retain victim data on servers even after ransom payments are made.
- Industry incidents like Klue and Change Healthcare demonstrate that paying multiple groups or trusting deletion claims is ineffective.
Why It Matters
This report provides empirical evidence supporting the long-standing advice against paying ransoms, highlighting that financial compliance often leads to repeated victimization. For security practitioners, it underscores the critical need to assume data retention by attackers regardless of payment, shifting focus toward prevention and robust backup strategies rather than negotiation.
Technical Details
- Survey Data: Proofpoint analyzed 953 companies, finding that more than 33% of those who paid were targeted again.
- Attack Evolution: The threat landscape has shifted from simple encryption-for-payment models to complex extortion using dual leverage (encryption + data theft).
- Case Studies:
- Klue: Paid hackers who claimed data deletion, but a separate group leaked data samples, exposing customers.
- Change Healthcare: Paid two distinct criminal groups separately due to affiliate disputes, failing to secure data protection.
- LockBit Takedown: UK police found victim data stored on gang servers post-payment, confirming non-deletion practices.
Industry Insight
- Strategic Shift: Organizations should treat ransomware as an inevitable breach scenario where data exfiltration is assumed, prioritizing immutable backups and incident response over negotiation budgets.
- Vendor Risk Management: Third-party vendors may claim data deletion post-breach; organizations must audit these claims and assume residual risk for their own data held by partners.
- Policy Enforcement: Internal policies must strictly prohibit ransom payments to avoid funding future attacks and signaling vulnerability to repeat offenders.
Disclaimer: The above content is generated by AI and is for reference only.