Paying Ransomware Criminals Doesn't Make Them Go Away. Surprise.
Authorities have been saying for years that paying ransoms is a bad idea. New data explains exactly why, in case anyone needed the numbers.
Proofpoint's latest survey found that 58 percent of UK organisations hit by ransomware paid up. Of those, 22 percent were extorted again regardless. So roughly one in five organisations that handed over money got a second demand for their trouble.
The UK figures sit close to the global average of 54 percent paying, though the regional spread is striking. Japan comes in at 19 percent. The US sits at 93 percent. Proofpoint points to regulatory environments, insurance incentives, recovery capability, and cultural attitudes to negotiation as the drivers behind that gap. What doesn't change much across borders is the underlying dynamic: ransomware generates enough operational pressure that a substantial chunk of victims pay, wherever they are.
The 37 percent global repeat-extortion rate is the number worth sitting with. UK organisations fared somewhat better than that average, but the basic problem remains the same. You cannot hold a criminal to their word. Paying doesn't undo an attack. It restarts a negotiation in which the attacker still holds the data, the decryption keys, and the threat of publishing everything they grabbed. The victim's leverage is exactly zero.
Operation Cronos, the law enforcement action that dismantled LockBit, turned a long-held assumption into documented fact: ransomware crews routinely kept victim data even after receiving payment. Before Dmitry Khoroshev's operation fell apart, this was informed suspicion. Cronos made it evidence. The idea that paying restores any kind of status quo took a serious hit.
Proofpoint also found that 2 percent of victims who paid never got their files back at all. Earlier this year, a coding error in Nitrogen's ESXi decryptor left a number of victims unable to fully restore access. This sort of thing is not rare. Attackers have no contractual obligation, no reputational incentive in any meaningful sense, and no reason whatsoever to deliver a working decryption tool once the money clears.
The only sensible response is to build resilience before any of this happens, not negotiate after.
AI's role: mostly in the run-up, not the payload
No security report in 2026 skips the AI section, and Proofpoint is no exception. In the UK, 65 percent of surveyed security practitioners said AI had made the attacks that precede ransomware more effective. That means phishing lures, business email compromise, malicious attachments, and credential harvesting campaigns that are harder to spot and faster to execute.
AI hasn't fundamentally changed ransomware itself yet, despite some recent speculation about where that might go. What it has done is improve the quality of the attack chains that deliver ransomware in the first place. More convincing impersonation. Better targeting. Faster reconnaissance once someone's already inside.
Proofpoint's chief strategy officer Ryan Kalember put it plainly: organisations still treating ransomware as an endpoint or recovery problem are looking at the wrong part of the attack. The entry points are people, credentials, and communications. That's where the AI-assisted improvement is happening, and that's where defences need to be.