Paying Cyber Ransoms May Trigger More Attacks, New Research Warns

A new cybersecurity report reveals that many organizations paying ransomware demands face repeated extortion, highlighting the financial, operational, and reputational risks of negotiating with cybercriminals.

TNN Cybersecurity Analysis Desk author photo
Wednesday, July 22, 2026

Organizations that choose to pay cybercriminals following ransomware attacks may be exposing themselves to an even greater wave of financial and operational risks, according to newly released cybersecurity research. Rather than ending an incident, ransom payments are increasingly becoming the beginning of a prolonged cycle of extortion, demonstrating how modern cybercrime has evolved into a persistent business model that targets victims repeatedly.

The findings come from a new report published by cybersecurity company Proofpoint, which surveyed 953 organizations to examine how businesses respond to ransomware and digital extortion attacks. The study found that more than one-third of organizations that agreed to pay ransom demands later received additional extortion requests from cybercriminals, challenging the belief that payment guarantees an end to the crisis.

For years, governments and cybersecurity agencies have advised businesses against negotiating with ransomware operators. Their guidance has been based on two primary concerns: paying criminals finances future attacks while simultaneously encouraging hackers to continue targeting organizations willing to transfer funds. The latest research strengthens this position by showing that even compliant victims frequently remain attractive targets for future exploitation.

Cybersecurity experts explain that ransomware operations have undergone a significant transformation. Earlier attacks typically focused on encrypting an organization's systems and demanding a single payment in exchange for a decryption key. Today's criminal groups employ far more sophisticated strategies by combining system disruption with data theft, allowing them to pressure victims through multiple forms of leverage.

This approach, commonly known as double extortion, enables attackers to threaten public disclosure of sensitive information even after systems have been restored. As a result, organizations face continuing legal, financial, and reputational risks regardless of whether they decide to pay.

The report also reinforces long-standing concerns regarding the credibility of cybercriminals' promises. Many ransomware groups claim that stolen files will be permanently deleted once payment is received. However, multiple real-world investigations have demonstrated that there is little evidence supporting those assurances, leaving organizations vulnerable to future data exposure.

One recent example involved market intelligence company Klue, where hackers obtained customer information affecting several cybersecurity firms. Although the company reached an agreement with the attackers, who claimed the stolen data had been destroyed, it was later revealed that another hacking group had obtained part of the same dataset. The incident highlighted how stolen information can continue circulating within criminal networks even after negotiations have concluded, exposing victims to additional extortion attempts.

Another widely cited case occurred during the 2024 cyberattack against Change Healthcare, one of the largest healthcare technology providers in the United States. Following the theft of sensitive medical information affecting approximately 192 million individuals, the company reportedly faced demands from multiple criminal groups after disputes emerged between the primary ransomware operators and their affiliated partners. Separate ransom payments were ultimately made in an effort to prevent the publication of confidential health records, illustrating the complexity of today's ransomware ecosystem.

Evidence gathered by international law enforcement agencies further supports these concerns. During operations targeting the notorious LockBit ransomware organization in 2024, investigators discovered that large volumes of victims' stolen data remained stored on the group's infrastructure long after ransom payments had allegedly resolved incidents. The findings demonstrated that payment alone offers no reliable guarantee that confidential information will actually be deleted.

From a strategic cybersecurity perspective, these developments reinforce the importance of prevention over negotiation. Organizations are increasingly encouraged to invest in resilient backup systems, multi-factor authentication, employee security awareness programs, endpoint protection technologies, and comprehensive incident response planning instead of relying on ransom payments as a recovery strategy.

The economic implications extend far beyond the ransom itself. Businesses affected by ransomware frequently incur additional expenses related to operational downtime, legal compliance, regulatory investigations, forensic analysis, customer notification, reputation management, and long-term cybersecurity improvements. In many cases, these indirect costs significantly exceed the original ransom demand.

For global brands, repeated extortion incidents also threaten consumer confidence. Customers, investors, and business partners increasingly evaluate organizations based on their ability to safeguard sensitive information, making cybersecurity an essential component of corporate governance and brand reputation rather than solely an information technology function.

The Proofpoint findings illustrate how cyber extortion has matured into a sustainable criminal enterprise built on repeated monetization of stolen data rather than isolated attacks. As threat actors continue refining their business models, organizations are likely to place even greater emphasis on proactive cyber resilience, rapid incident detection, and long-term risk management to reduce both financial losses and reputational damage in an increasingly hostile digital environment.

Paying Cyber Ransoms May Trigger More Attacks, New Research Warns

News You Should See

Cloudflare Unveils Kitesurf to Power the Next Generation of AI Agents

TechCrunch Expands Community Strategy with New Call for Disrupt 2026 Side Events

Kimi Sandbox Escape Raises New Questions Over AI Security Testing Standards

Airbnb Accelerates AI Strategy With Faster Product Development and Smarter Search

SpaceX Chooses Natural Gas Over Solar to Power Terafab Chip Megaproject

TechCrunch Disrupt 2026 Positions AI-Era Company Building at the Center of Startup Strategy

Latest News

Cloudflare Unveils Kitesurf to Power the Next Generation of AI Agents

Cloudflare has introduced Kitesurf, a browser engineered for AI agents instead of humans, aiming to reduce computing costs while improving security and scalability for autonomous AI workloads.

TechCrunch Expands Community Strategy with New Call for Disrupt 2026 Side Events

TechCrunch is inviting founders, investors, and organizations to host Side Events during Disrupt 2026, expanding networking opportunities and strengthening the startup ecosystem surrounding the conference.

Kimi Sandbox Escape Raises New Questions Over AI Security Testing Standards

Analysis of the reported Kimi AI sandbox escape, its implications for AI cybersecurity testing, enterprise risk management, and the evolving competition in advanced AI safety.

Airbnb Accelerates AI Strategy With Faster Product Development and Smarter Search

Airbnb says artificial intelligence is reducing software development time, lowering support costs, and powering a new AI search experience as the company deepens its AI-first strategy.

SpaceX Chooses Natural Gas Over Solar to Power Terafab Chip Megaproject

SpaceX plans to power its Terafab semiconductor facility in Texas with dedicated natural gas plants and large battery systems, highlighting the growing energy demands of AI infrastructure and data centers.

TechCrunch Disrupt 2026 Positions AI-Era Company Building at the Center of Startup Strategy

TechCrunch Disrupt 2026 will bring together founders, investors, and technology leaders with more than 200 sessions focused on AI, fundraising, scaling businesses, infrastructure, and startup growth strategies.

New Mexico Court Expands Landmark Ruling Against Meta With $567 Million Child Safety Order

A New Mexico court ordered Meta to pay an additional $567 million and implement major child safety reforms, increasing the company's total liability to $942 million in a landmark legal battle over youth protection and platform accountability.

Google Wallet Turns Family Payments Into a Controlled Digital Finance Experience

Google Wallet now lets parents create secure balances for children under 18, set spending limits, monitor transactions, and pause payments through parental controls.

Summer Boots Become a Statement of Style, Identity, and Generational Change

Summer 2026 sees Gen Z embracing boots with shorts, skirts, and dresses, turning an unexpected footwear choice into a cultural and commercial fashion trend.