★ INSERT COINNOW PLAYING: VENTURESHIGH SCORE: $100M ARR★ NEW STAGE UNLOCKED: ABOUT MEPRESS START★ DEMO DAY 04:00:00
★ INSERT COINNOW PLAYING: VENTURESHIGH SCORE: $100M ARR★ NEW STAGE UNLOCKED: ABOUT MEPRESS START★ DEMO DAY 04:00:00
◀ BACK TO FEED
NEWSCYBERSECURITYJUL 22, 2026

Ransom payments often trigger fresh extortion

New research suggests paying attackers frequently fails to close an incident because stolen data and a victim’s willingness to pay remain exploitable.

Ransom payments often trigger fresh extortion

Paying a ransomware demand is often presented as a way to restore operations quickly. New evidence shows that payment may not end the attack—and can make the victim more attractive for another one.

What happened

A survey of 953 organisations found that more than one-third of those that paid a ransom later received another extortion demand.

Attackers may retain stolen information after payment, sell it to another criminal group or return with a new threat to publish it. Law-enforcement investigations have repeatedly found victim data stored by ransomware operators even when a company believed it had paid for deletion.

The research does not mean every payer will be targeted again, and survey results depend on how organisations report incidents. It nevertheless reinforces a core limitation of ransom negotiations: the victim cannot independently verify that criminals have destroyed data or surrendered every copy.

Why it matters

Payment may restore access to encrypted systems, but it does not repair the security weakness that enabled the intrusion. It also signals that the organisation can and will transfer money under pressure.

Companies that treat payment as the incident-response plan risk returning to normal operations without identifying persistent access, compromised credentials or affected suppliers.

The bigger picture

Ransomware has evolved from simple encryption into a broader extortion economy built around data theft, disruption and repeated leverage.

That changes the investment priority. Backups remain essential, but resilience also requires network segmentation, identity controls, recovery exercises and clear authority for shutting down affected systems. The aim is not merely to avoid paying; it is to make the organisation capable of operating and recovering even when attackers hold data or systems hostage.

#RANSOMWARE#CYBER RESILIENCE#EXTORTION#DATA SECURITY