Making a ransomware ransom payment is less a resolution than an opening bid: new data from cybersecurity firm Proofpoint finds that more than one-third of the 953 companies it surveyed were hit with a second extortion demand after paying up the first time.
The report, published this week, puts hard numbers on something security researchers have argued for years: there is no good-faith negotiation with an extortion racket. Once you have demonstrated willingness to pay, you become a known quantity worth revisiting.
Why Ransomware Ransom Payment Rarely Closes the Book
Ransomware has evolved well beyond a one-and-done transaction. Proofpoint’s findings show attackers now layer multiple forms of leverage, holding stolen data as a separate threat even after a decryption key has been handed over. The implicit promise, that paying will make the problem go away, is structurally hollow: the criminals have every incentive to keep the data and every reason to come back.
The Change Healthcare breach in 2024 is the clearest recent illustration. The Russian-speaking ransomware gang ALPHV/BlackCat claimed responsibility, alleging it had stolen 6TB of sensitive health and medical data covering the majority of Americans, some 192 million people.
According to Wired, on 1 March 2024 a Bitcoin address connected to ALPHV/BlackCat received 350 bitcoins in a single transaction, worth approximately $22 million, in exchange for a decryption key and a pledge to delete the stolen data. The pledge, predictably, did not hold.
An ALPHV affiliate then publicly alleged on the cybercriminal underground forum RAMP that the group had kept the full payment without sharing the agreed cut. The affiliate used the publicly visible Bitcoin transaction as proof. Change Healthcare ended up paying separate ransoms to both the gang and its affiliate to try to keep the data off the internet, a second payment that the original $22 million was supposed to make unnecessary.
The total financial cost of the breach, according to DataBreachCost.com‘s summary of UnitedHealth Group’s SEC filings, crossed $2.45 billion and was still accruing through 2026, making it the largest healthcare breach in US history by cost. The $22 million ransom did not prevent a single dollar of that.
Deleted Data Is a Promise, Not a Fact
The habit of trusting hackers’ deletion promises has a long, unhappy track record. Last month, a breach at market research firm Klue exposed data belonging to its customers, including several cybersecurity companies. Klue said it reached a deal with the attackers, who claimed to have deleted everything. A separate hacking group subsequently surfaced with a sample of the same stolen data, leaving Klue’s customers exposed to fresh extortion demands.
UK law enforcement confirmed the pattern from the other side during the 2024 takedown of the LockBit ransomware gang. Police reported finding victims’ stolen data stored on LockBit’s servers long after those victims had paid their ransoms. The delete-on-payment guarantee is, in practice, unenforceable by design.
Governments have pushed this line for years, and the money flows explain why. A letter from a US Senate office to CISA, dated 29 April 2024 and citing a 2022 Senate report, noted that in 2021 nearly 75% of all ransomware revenue went to Russia-linked entities. Payments are made almost exclusively in cryptocurrency, typically Bitcoin, because the method is decentralised, pseudonymous, and irreversible. There is no chargeback, no dispute process, no recourse.
The Proofpoint data sits inside a broader shift: ransomware is no longer a single extortion event but a sustained relationship, and not the kind any security team wants. Attackers retain data, share it across affiliate networks, and return to proven payers. Paying once does not buy silence. It buys confirmation that you are worth targeting again.
The next pressure point for organisations will be regulatory: several jurisdictions are moving towards mandatory breach disclosure rules that would force companies to surface these incidents rather than quietly pay and hope for the best. When that disclosure is required regardless of payment, the financial logic of paying collapses further.
