VYPR
trendPublished Jul 22, 2026· 1 source

Ransomware Crews Double Down on Extortion as Victims Continue to Pay

New research indicates a significant portion of ransomware victims pay ransoms, with many facing repeat extortion, underscoring the unreliability of criminal promises.

Despite persistent warnings from cybersecurity experts and law enforcement, a substantial number of organizations continue to pay ransom demands when hit by ransomware attacks. A recent report from Proofpoint reveals that 58 percent of extorted organizations in the UK opt to pay, a figure that aligns closely with the global average of 54 percent. This trend is not uniform across regions, with payment rates varying significantly, from a low of 19 percent in Japan to a high of 93 percent in the US, attributed to differences in regulatory environments, recovery capabilities, insurance policies, and cultural negotiation norms.

The core takeaway from the data is that the immense pressure exerted by ransomware attacks compels a significant portion of victims to pay, regardless of the potential consequences. Even among those who do pay, the situation often fails to resolve cleanly. Worryingly, 22 percent of organizations that pay a ransom are subjected to repeat extortion by the same or different criminal groups. This highlights the fundamental untrustworthiness of cybercriminals; paying the ransom does not guarantee an end to the threat or the return of data.

Law enforcement actions, such as Operation Cronos which dismantled the LockBit ransomware gang, have provided concrete evidence that cybercriminals often retain victim data even after receiving payment. This undermines the perceived 'status quo' restoration that victims might expect from a payout. Furthermore, the Proofpoint report indicates that 2 percent of victims who paid a ransom never recovered their files at all, a stark reminder that payment is not a foolproof solution for data recovery.

While the primary focus remains on preventing attacks and building resilience, the reality of ransomware economics is that attackers can continue to extort victims without necessarily fulfilling their end of the bargain. The threat of data publication or re-encryption remains a potent weapon in their arsenal, even after a payment has been made. This underscores the critical need for robust cybersecurity defenses and incident response plans that do not rely on the assumption that a ransom payment will resolve the issue.

The report also touches upon the evolving role of Artificial Intelligence (AI) in the cybersecurity landscape. In the UK, 65 percent of security practitioners surveyed believe AI has intensified the attacks that precede ransomware, particularly in areas like malicious links, business email compromise (BEC), malicious attachments, and credential harvesting. While AI is not yet a dominant component of ransomware payloads themselves, its application in crafting more convincing phishing lures, sophisticated impersonation attempts, and accelerated system reconnaissance is significantly sharpening attack vectors.

Ryan Kalember, Chief Strategy Officer at Proofpoint, emphasized that AI has not fundamentally altered ransomware itself but has materially improved the initial stages of attacks. He noted that attackers are leveraging AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale. This shift means that organizations viewing ransomware solely as an endpoint or recovery problem are missing the crucial human and identity-centric elements where these attacks most frequently begin.

Ultimately, the data reinforces the long-standing advice that the most effective defense against ransomware is not to pay, but to build organizational cyber-resilience. This includes strong preventative measures, comprehensive detection capabilities, and well-rehearsed incident response plans. The continued willingness of victims to pay, coupled with the evolving sophistication of attack methods, including AI-enhanced phishing, presents an ongoing challenge for the cybersecurity community.

Synthesized by Vypr AI