Bad news: Paying a ransomware demand could encourage hackers to come back and ask for more.

Bad news: Paying a ransomware demand could encourage hackers to come back and ask for more.

A hooded figure in front of a laptop. Numerical symbols obscure his face and seem to come out of his head
(Image credit: Getty Images)

  • The Proofpoint 2026 AI-Era Ransomware report reveals that 54% of victims paid attackers despite warnings.
  • 37% experienced repeated extortion after paying; 2% paid but never regained access to files
  • Experts Call for Prevention: Phishing Awareness, Offline Backups, and AI-Driven Endpoint Protection

Security researchers Proofpoint have apparently proven once again that paying ransomware perpetrators doesn’t guarantee they’ll go away for good. In fact, they have proven that in many cases they will simply come back for more because they know they can get paid.

The company’s “2026 AI-Era Ransomware Report,” based on a survey of nearly 1,000 security professionals across 12 markets, reveals that globally, more than half (54%) of affected organizations have paid their attackers to regain access to locked files and prevent them from sharing stolen documents on the dark web.

This is despite repeated calls from law enforcement and the cybersecurity industry not to interact with the attackers and under no circumstances pay the demanded ransom. Proofpoint argues that the real pressure organizations experience when facing disruption is, in many cases, simply too great to tolerate.

Request a second payment

The logic behind the “don’t pay” argument is simple: by paying, victims incentivize attackers to do more damage and fund future attacks. At the same time, there is no guarantee that the decryption keys will work, that the attackers will actually delete the files they stole, and that they will not strike again in a few weeks.

This last argument has now been proven. While about half (56%) of victims paid a ransom and regained access, more than a third (37%) faced a second extortion demand shortly after paying. Another 2% paid and never regained access at all.

Instead of paying the ransom demand, the industry suggests businesses protect their premises by educating employees about the dangers of phishing, maintaining up-to-date backups in offline storage, and running (if possible, AI-powered) endpoint detection and protection services across the entire technology stack.

Via TechCrunch

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!



Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). During his career, which spans more than a decade, he has written for numerous media outlets, including Al Jazeera Balkans. He has also hosted several modules on content writing for Represent Communications.

Exit mobile version