DTWdailytechwire
Tech Intelligence, Wired Daily
Policy

Paying Ransomware Gangs Once Makes You a Repeat Target

New enterprise data shows that over one-third of companies face second extortion demands after paying, as criminal groups retain stolen data despite promises to delete it.

AS
Arjun S. Mehta
Staff Writer · Singapore
Jul 23, 2026
5 min read
Paying Ransomware Gangs Once Makes You a Repeat Target
Paying Ransomware Gangs Once Makes You a Repeat TargetCredit: Donat Sorokin / Getty Images

The Payment Paradox

When a company's systems are locked by ransomware or its data is stolen, the decision to pay often feels like the fastest path to resolution. But new research quantifies what security professionals have long suspected: paying once doesn't end the relationship with attackers. It deepens it.

Proofpoint surveyed 953 organizations and found that more than one-third of those that paid a ransom demand were subsequently hit with a second extortion attempt. The finding challenges the transactional logic many executives apply to these situations, where payment is seen as closing a chapter rather than opening a new one.

At DailyTechWire, we've tracked the evolution of ransomware economics across Asia and globally, and the shift from single-event attacks to sustained extortion campaigns represents a structural change in how criminal groups operate. The incentive structure is clear: a company that pays once has demonstrated both the capacity and willingness to transfer funds under pressure.

Why Criminals Don't Delete Your Data

The core promise in most ransom negotiations is straightforward: pay, and the stolen data will be deleted. Evidence increasingly shows this promise is unreliable at best, and deliberately false at worst.

Market research firm Klue experienced this firsthand in 2025. The company negotiated with hackers who claimed to have deleted customer data, including information from several cybersecurity firms. Shortly after, a separate hacking group released a sample of the same stolen data, proving it had never been destroyed and remained in circulation among criminal networks.

Change Healthcare's 2024 breach illustrates the problem at scale. After Russian-speaking ransomware operators stole health and medical records of approximately 192 million Americans, a dispute erupted between the primary gang and their affiliates. Change Healthcare ended up paying ransoms to both groups to prevent the data from being published. The incident revealed how stolen data can become a tradable asset among multiple criminal entities, each capable of independent extortion.

U.K. law enforcement provided direct confirmation during their 2024 operation against LockBit, one of the most prolific ransomware operations globally. When authorities gained access to LockBit's infrastructure, they discovered victims' data still stored on servers long after those organizations had paid ransoms and been assured of deletion. The data wasn't just retained, it was catalogued and accessible for future use.

From Transaction to Relationship

The shift in attacker behavior reflects a maturation of the ransomware economy. Early ransomware campaigns operated on volume: encrypt many targets, collect payments quickly, move to the next batch. Modern extortion groups have adopted a relationship model, recognizing that a proven payer represents more value over time than a one-time transaction.

This evolution has been particularly visible in attacks targeting mid-sized enterprises across Southeast Asia and India, where security budgets often lag behind digitization efforts. Organizations in these markets face a double bind: paying is often the only way to restore operations quickly, but doing so marks them as viable targets for repeated attacks.

The technical mechanics enable this persistence. Once attackers exfiltrate data, they hold a permanent lever. Even if they provide decryption keys or remove immediate access barriers, the stolen information remains under their control. Cloud storage and encrypted file-sharing services make it trivial for criminal groups to retain copies indefinitely, with negligible ongoing cost.

The Economics of Repeat Extortion

For criminal groups, the calculus is straightforward. Attacking a new target requires reconnaissance, initial access development, lateral movement through networks, and data exfiltration, all resource-intensive activities with uncertain payoff. Returning to a previous payer requires only a message and a payment portal. The infrastructure is already in place, the victim's willingness to pay is established, and the stolen data provides ongoing leverage.

Proofpoint's data suggests this is not an occasional tactic but a systematic approach. More than one in three payers face follow-up demands, a rate high enough to indicate that repeat extortion is a core part of many groups' business models.

The implications extend beyond individual organizations. When companies pay ransoms quietly and repeatedly, they sustain the operational viability of criminal infrastructure. Each payment funds servers, developers, affiliates, and the next wave of attacks. It also signals to other criminal groups that certain industries or geographies are willing payers, concentrating attacks on those sectors.

Policy Tensions and Real-World Constraints

Governments across the U.S., Europe, and increasingly in Asia have urged organizations not to pay ransoms. The logic is sound from a systemic perspective: if no one pays, the ransomware model collapses. But individual organizations operate under different constraints.

A hospital with patient care at stake, a logistics company facing supply chain disruption, or a financial services firm with regulatory reporting obligations may determine that paying is the least damaging option among bad choices. The gap between policy guidance and operational reality remains wide.

Some jurisdictions have considered or implemented regulations requiring disclosure of ransom payments, or in limited cases, prohibiting payments altogether. Singapore's Cybersecurity Act amendments and South Korea's evolving data protection framework both touch on ransom payment obligations, though enforcement remains inconsistent.

The challenge is that policy operates at the macro level while decisions are made at the micro level, under time pressure and incomplete information. An executive facing a 48-hour deadline to restore systems is rarely positioned to weigh the systemic consequences of funding cybercrime infrastructure.

What Changes the Pattern

Breaking the repeat extortion cycle requires changes at multiple levels. For individual organizations, the most effective defense remains prevention: segmented networks, offline backups, endpoint detection, and incident response planning reduce both the likelihood of successful attacks and the leverage attackers gain if they do breach defenses.

When breaches occur, the decision calculus shifts. Organizations with robust backups and tested recovery procedures have genuine alternatives to payment. Those without such preparations face a constrained choice set, which attackers understand and exploit.

At the industry level, information sharing about attacker behavior, payment demands, and post-payment experiences can help organizations make more informed decisions. Several regional CERTs and industry groups across Asia have begun facilitating these exchanges, though participation remains uneven.

Law enforcement action has shown some effect. The LockBit disruption temporarily reduced that group's activity, and similar operations against other major ransomware brands have created friction in criminal ecosystems. But these groups are resilient, often rebranding and reconstituting after takedowns.

The longer-term shift may come from the insurance market. Cyber insurance policies increasingly impose conditions on ransom payments, requiring specific security controls and incident response procedures. As insurers refine their models and recognize the repeat extortion risk, policy terms may begin to shape organizational behavior more effectively than government guidance alone.

The Proofpoint data underscores a reality that policy and technology must address together: paying a ransom is not a transaction with a defined end. It is an entry point into an ongoing relationship with actors whose incentive is to maximize extraction, not to honor agreements. Until that structural dynamic changes, organizations that pay once should prepare for the likelihood that they will be asked to pay again.

Read next
Policy

Florida Teen Withdraws Case Days Before Meta Addiction Trial

Daniel R. Whitfield · 5 min
Policy

Paramount Clears Brussels Hurdle in Warner Bros. Mega-Deal

Marcus Halloran · 4 min
Policy

Apple's Financing Mechanism Now Targets App Access

Marcus Halloran · 4 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.