cd /news/ai-policy/if-you-pay-a-hacker-s-ransom-chances… · home topics ai-policy article
[ARTICLE · art-69066] src=techcrunch.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

If you pay a hacker's ransom, chances are that they'll come back for more

Over one-third of companies that paid a hacker's ransom were hit with a second extortion demand, according to a report by cybersecurity firm Proofpoint. The survey of 953 companies found that ransomware attacks have evolved into multi-stage extortion efforts, with hackers often retaining stolen data even after payment. Security researchers and law enforcement have long warned that paying ransoms does not guarantee data deletion and can lead to further demands.

read2 min views1 publishedJul 22, 2026
If you pay a hacker's ransom, chances are that they'll come back for more
Image: TechCrunch AI

Governments have long warned not to pay a hacker’s ransom demands, arguing that doing so only lets criminals profit from their cyberattacks and funds the next one. There’s also another reason: The hackers are unlikely to leave you alone if you pay up once, and many will come back demanding more.

In a report published Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand. The findings underscore the long-held understanding among security researchers and network defenders that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away.

Proofpoint’s data shows that ransomware attacks and extortion attacks have evolved from a single transaction where hackers would get paid once and move on, into an effort using multiple forms of leverage, such as retaining stolen data under the threat of publicly releasing it.

While hackers have claimed in the past that they will delete or destroy the victim’s stolen data, past incidents have shown that not to be the case. Last month, a hack at market research firm Klue exposed data belonging to its customers, including several cybersecurity firms. The company said it struck a deal with the hackers, who claimed to have deleted the data, but the company later conceded that a separate hacking group swiped a sample of the company’s stolen data, leaving its customers exposed to potential future extortion demands.

A similar situation befell Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, some 192 million people. Amid a dispute between the hackers and their affiliates (criminal groups often subcontract out attacks), Change Healthcare paid separate ransoms to both groups of criminals to keep the sensitive medical data off of the internet.

Security researchers have long suspected that ransomware gangs and extortion rackets will keep hold of the victim’s stolen data, even after a payment is made. U.K. law enforcement confirmed this during their takedown efforts targeting the prolific LockBit ransomware gang in 2024. Police said that they found victims’ stolen data stored on LockBit’s servers long after they had paid the ransom.

── more in #ai-policy 4 stories · sorted by recency
── more on @proofpoint 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/if-you-pay-a-hacker-…] indexed:0 read:2min 2026-07-22 ·