Chrony

Paying Ransom Fuels More Attacks

· news

If You Pay a Hacker’s Ransom, Chances Are They’ll Come Back for More

The latest report from cybersecurity giant Proofpoint confirms what experts have long warned: paying ransom only funds the next attack. The numbers are stark: over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand.

This is not an anomaly or outlier – it’s the norm. Cybersecurity researchers have consistently stated that paying ransom creates a never-ending cycle of extortion, and Proofpoint’s report demonstrates this reality. The company’s data supports the notion that hackers are in it for the long haul, rather than seeking short-term payoffs.

The case of Klue, a market research firm hacked last month, illustrates this point. Despite striking a deal with the hackers to delete stolen customer data, a separate hacking group swooped in and stole a sample of the data, leaving customers exposed to future extortion demands.

Change Healthcare faced a similar situation in 2024 when a Russian-speaking ransomware gang stole nearly 192 million people’s medical data. Amid a dispute between the hackers and their affiliates, Change Healthcare paid separate ransoms to both groups of criminals to keep the sensitive data off the internet.

The evidence is clear: paying ransom does not work and only makes things worse. Hackers are emboldened by the knowledge that companies will pay them off, allowing them to continue pushing the limits of what they can get away with.

This is not just a problem for companies or governments; it affects us all. By enabling ransomware and extortion attacks through our actions – or lack thereof – we’re also enabling a culture of impunity that emboldens these groups.

Companies need to rethink their incident response plans and take proactive measures to prevent these types of attacks in the first place. Governments must step up efforts to take down ransomware gangs and hold them accountable for their crimes. And individuals need to be more vigilant about how they’re supporting these groups through their actions – or lack thereof.

The truth is, paying ransom only feeds the beast. Until we start treating this like the serious problem it is, we’ll continue playing whack-a-mole with hackers, forever chasing them down and always one step behind.

It’s time to stop making excuses and start taking action. We can’t afford to wait for someone else to fix the problem; we need to take matters into our own hands and demand a better solution – starting now.

Reader Views

  • RJ
    Reporter J. Avery · staff reporter

    It's time for companies and governments to face the hard truth: paying ransom is not a viable solution to cybersecurity threats. By continuing down this path, we're essentially funding our own vulnerabilities and perpetuating a culture of extortion. What's often overlooked in these discussions is the psychological factor – hackers are not just motivated by financial gain, but also by the thrill of outsmarting their targets. As long as companies prioritize short-term fixes over long-term security, they'll remain vulnerable to repeated attacks.

  • CM
    Columnist M. Reid · opinion columnist

    The article hits on some crucial points about paying ransom fueling more attacks, but I think it's worth drilling down further on what this means for smaller businesses and individuals who can't afford the hefty sums demanded by hackers. For them, negotiating with ransomware gangs is often a last resort – one that puts their very existence at risk if they're unable to meet the extortion demands. As we continue to see more of these attacks, it's essential that policymakers explore ways to hold these perpetrators accountable and provide support for those most vulnerable to this form of cybercrime.

  • AD
    Analyst D. Park · policy analyst

    While the report's findings are alarming, we must also acknowledge that many companies don't have the luxury of choosing between paying ransom and absorbing significant financial losses. Failing to pay may lead to reputational damage, data breaches, and regulatory consequences. Therefore, policymakers need to weigh in with more comprehensive cybersecurity measures and support for affected businesses, rather than simply condemning the practice of paying ransom as a moral failing.

Related articles

More from Chrony

View as Web Story →