Governments have lengthy warned to not pay a hacker’s ransom calls for, arguing that doing so solely lets criminals profit from their cyberattacks and funds the following one. There’s additionally another excuse: The hackers are unlikely to go away you alone should you pay up as soon as, and lots of will come again demanding extra.
In a report printed Wednesday, cybersecurity large Proofpoint mentioned it surveyed 953 firms and found that over one-third of firms that paid a hacker’s ransom had been hit with a second extortion demand. The findings underscore the long-held understanding amongst safety researchers and community defenders that it’s inconceivable to barter in good religion with an extortion racket as a result of there’s no incentive for the opposite aspect to truly stroll away.
Proofpoint’s knowledge reveals that ransomware assaults and extortion assaults have advanced from a single transaction the place hackers would receives a commission as soon as and transfer on, into an effort utilizing a number of types of leverage, resembling retaining stolen knowledge underneath the specter of publicly releasing it.
Whereas hackers have claimed prior to now that they may delete or destroy the sufferer’s stolen knowledge, previous incidents have proven that to not be the case.
Final month, a hack at market analysis agency Klue uncovered data belonging to its customers, together with a number of cybersecurity companies. The corporate mentioned it struck a take care of the hackers, who claimed to have deleted the info, however the firm later conceded {that a} separate hacking group swiped a pattern of the corporate’s stolen knowledge, leaving its prospects uncovered to potential future extortion demands.
An analogous scenario befell Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the well being and medical knowledge of nearly all of folks in America, some 192 million folks. Amid a dispute between the hackers and their associates (felony teams usually subcontract out assaults), Change Healthcare paid separate ransoms to each teams of criminals to maintain the delicate medical knowledge off of the web.
Safety researchers have lengthy suspected that ransomware gangs and extortion rackets will maintain maintain of the sufferer’s stolen knowledge, even after a cost is made. U.Ok. legislation enforcement confirmed this throughout their takedown efforts concentrating on the prolific LockBit ransomware gang in 2024. Police mentioned that they discovered victims’ stolen knowledge saved on LockBit’s servers lengthy after they’d paid the ransom.
While you buy by way of hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.

