YYaaa News

Proofpoint: Over One-Third of Companies That Pay Ransom Get Hit Again | Paying Is a Down Payment, Not a Close-Out

TL;DR

Proofpoint's survey of 953 companies found over one-third of those who paid ransom faced a second extortion demand from the same attackers.

Cybersecurity giant Proofpoint published its annual report Wednesday. In a survey of 953 companies, over one-third of those who paid attackers' ransom faced a second extortion demand. Ransomware and extortion have evolved from single-payment transactions into ongoing operations leveraging multiple pressure points — public leaks, secondary ransoms, threats to release retained stolen data.

Attackers have historically claimed they delete or destroy victim data after payment. Prior incidents show otherwise. UK law enforcement's 2024 takedown of the LockBit ransomware group confirmed this: police found victim data still fully stored on LockBit servers long after ransoms were paid, including data from victims who had paid years earlier.

The signal to CISOs is clear at the executive level: paying ransom isn't closing an incident, it's a down payment on the next attack. Proofpoint stops short of saying "don't pay," but puts the secondary-extortion rate on the report cover — the goal is to shift enterprise decision inertia away from "pay and it's over."

via TechCrunch
Proofpoint 報告|953 家公司樣本中,付了贖金的公司超三分之一遭第二次勒索