If you pay a hacker’s ransom, chances are that they’ll come back for more

A new report from Proofpoint reveals that over one-third of companies that pay a hacker's ransom are targeted again by the same or different extortionists. Cybersecurity experts warn that paying ransoms is ineffective because it incentivizes further attacks and provides no guarantee that stolen data will be destroyed.
Why it matters
This data provides critical evidence for the cybersecurity industry's stance against paying ransoms, highlighting the persistent threat of repeat extortion.
Governments have long warned not to pay a hacker’s ransom demands, arguing that doing so only lets criminals profit from their cyberattacks and funds the next one. There’s also another reason: The hackers are unlikely to leave you alone if you pay up once, and many will come back demanding more.
In a report published Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand. The findings underscore the long-held understanding among security researchers and network defenders that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in