Full Report
The long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion racket because there's no incentive for the other side to actually walk away.
Analysis Summary
# Industry News: The High Cost of Compliance: Ransom Payments Fuel Recurring Extortion
## Summary
A new report from cybersecurity leader Proofpoint reveals that over one-third of companies that pay a ransom are targeted with secondary extortion demands. The data suggests that paying hackers no longer guarantees data deletion or an end to the attack, as criminal groups increasingly use "multiple forms of leverage" to maximize profits.
## Key Details
- **Date:** July 22, 2026
- **Companies Involved:** Proofpoint (Lead Researcher), Klue, Change Healthcare, LockBit (Threat Actor)
- **Category:** Market Analysis & Threat Intelligence
## The Story
The traditional "honor among thieves" narrative in ransomware—the idea that paying a ransom ensures data recovery and deletion—is effectively dead. Proofpoint’s survey of 953 companies highlights a predatory shift in the cybercrime ecosystem. Threat actors are no longer treating ransomware as a single transaction; instead, they are adopting a "double or triple dip" strategy.
Recent high-profile cases illustrate this trend. **Change Healthcare** was forced to pay two separate ransoms to different criminal entities (the original gang and their affiliates) after falling victim to an internal dispute among the hackers. Similarly, the market research firm **Klue** believed they had secured a data deletion agreement, only to find that other threat actors had retained copies of the stolen data to initiate new extortion cycles. Law enforcement operations, such as the 2024 takedown of **LockBit**, have confirmed that hackers rarely delete data as promised, even after receiving payment.
## Business Impact
### For the Companies Involved
- **Financial Double-Jeopardy:** Companies face the risk of paying millions only to be extorted again weeks or months later, leading to unpredictable legal and recovery costs.
- **Reputational Damage:** Conceding that a ransom was paid—only for the data to be leaked anyway—erodes customer trust and increases the likelihood of class-action litigation.
### For Competitors
- **Target Shift:** As some sectors become "reliable payers," threat actors may pivot away from hardened targets to concentrate on industries where the "willingness to pay" is high, regardless of the recurring risk.
### For Customers
- **Permanent Exposure:** End-users must assume that once their data is exfiltrated, it is permanently in the wild, regardless of any "guarantees" made by the victim company or the hacker.
### For the Market
- **Insurance Volatility:** Cyber insurance providers may tighten "pay-out" clauses or significantly raise premiums for companies that lack robust recovery backups, as the ROI on paying ransoms continues to plummet.
- **Decline in Negotiation Efficacy:** The perceived value of "Ransomware Negotiation" services may shift toward recovery and forensic analysis rather than financial settlement.
## Technical Implications
The report highlights the evolution of **multi-extortion tactics**. Hackers are moving beyond simple encryption to persistent data exfiltration and "affiliate-jumping," where stolen credentials or data are traded between different criminal subgroups to ensure the victim is hounded by multiple entities simultaneously.
## Strategic Analysis
- **Market Positioning:** Proofpoint strengthens its position as a thought leader in "identity-centric" and "human-centric" security by proving that the financial end-game of cybercrime is fundamentally broken.
- **Competitive Advantage:** Firms specializing in immutable backups and rapid disaster recovery will see increased demand over those offering purely defensive perimeter solutions.
- **Challenges:** Organizations face a "damned if you do, damned if you don't" scenario. Paying may fail to protect data, but not paying may lead to immediate outages in critical infrastructure (as seen with Change Healthcare).
## Industry Reactions
- **Analyst Opinions:** This data reinforces the long-standing government stance (FBI/CISA) that ransom payments fund future criminal R&D without guaranteed protection for the victim.
- **Market Response:** There is a growing movement toward making ransom payments illegal or strictly regulated, though this remains controversial in sectors providing essential services.
## Future Outlook
- **Predictions:** Expect more "extortion-only" attacks where hackers bypass encryption entirely and move straight to data theft, knowing that the threat of a leak is more profitable than a system lockout.
- **What to watch for:** Regulatory changes that may require companies to disclose not just the breach, but the specific terms and outcomes of any ransom negotiations.
## For Security Professionals
Security leaders should use this data to pivot board-level conversations away from "how much should we pay?" to "how do we ensure we never have to decide?" Practitioners must prioritize **data egress monitoring** and **segmentation**, assuming that any data "recovered" via ransom is still compromised and will likely resurface in the future.