
More than one-third of organisations that paid a ransom following a cyberattack later received another demand from the attackers, according to new research from Proofpoint. The findings indicate that payments do not guarantee stolen data will be deleted or prevent criminals from targeting the same victim again.
Proofpoint surveyed 953 security professionals across 12 countries and 20 industries between March and April 2026. Among organisations affected by ransomware, 65% said AI had made attacks more effective, particularly through phishing, impersonation and credential theft.
Attackers Use Several Forms of Pressure
Ransomware operations increasingly combine system encryption with data theft. Attackers may demand one payment to restore access and another to prevent the release or sale of stolen information.
Proofpoint’s official research announcement found that more than one-third of companies that paid received a second extortion demand. The report said this reflects a shift from single-payment attacks towards campaigns that use stolen data as continuing leverage.
Criminal groups often promise to destroy stolen files after receiving payment. However, victims have little way to confirm whether every copy has been deleted or whether affiliates and other hackers still possess the information.
Klue Customers Face Continued Exposure
A recent attack on market research company Klue showed how stolen information can remain available after negotiations. The Icarus ransomware group told Klue it was taking steps to delete customer data, but another hacking group later claimed it had accessed samples from Icarus’s systems.
That second group attempted to contact affected Klue customers directly. Klue advised customers not to pay and to request random data samples before accepting claims that the group held complete copies of their information.
Change Healthcare Received Another Demand
UnitedHealth-owned Change Healthcare paid a reported $22 million ransom after a February 2024 attack disrupted healthcare payments and pharmacy services across the United States. The ALPHV ransomware operation then shut down without paying the affiliate responsible for the intrusion.
The affiliate reportedly retained the stolen information and later used another ransomware platform to issue an additional demand. The breach ultimately affected information belonging to about 192 million people.
Police Find Data Retained After Payments
UK law enforcement found further evidence during its 2024 operation against the LockBit ransomware group. Investigators discovered information belonging to victims who had already paid ransoms, showing that LockBit had retained their files despite assurances that the data would be removed.
Government agencies generally advise organisations not to pay because payments finance criminal operations and do not guarantee recovery or deletion. Proofpoint’s findings show that organisations may still face further extortion even after agreeing to an attacker’s initial demand.
Featured image credits: Magnific.com
For more stories like it, click the +Follow button at the top of this page to follow us.
