Ransomware Re-Extortion: Why Paying Doesn't End the Attack

Fresh Proofpoint survey data shows that paying a ransom rarely ends the story, with repeat extortion hitting victims even after the first payment clears.

Ransomware Re-Extortion: Why Paying Doesn't End the Attack

Ransomware groups are increasingly returning for a second payment from organizations that already paid once, according to new survey data from Proofpoint. The figures highlight a hard truth for website owners, hosting customers, and IT teams: settling the first ransom rarely restores security, and in a worrying share of cases it simply opens the door to a second extortion attempt. Operators walk away with the money, keep the stolen data, and return later when pressure builds again.

For any business running production websites, customer portals, or WordPress installations on shared, VPS, or dedicated infrastructure, the lesson is straightforward. Payment is not a recovery strategy. Building cyber resilience into the environment, the people, and the response process is. That starts with understanding how repeat extortion actually works in practice.

Key Takeaways

Technical illustration explaining Key Takeaways for ransomware re-extortion
Key Takeaways shows a practical part of ransomware re-extortion.
  • Around 58% of affected UK organizations admitted to paying a ransom, slightly above the global average of 54%.
  • Globally, 22% of organizations that paid a ransom were extorted again by the same or an affiliated group.
  • 2% of paying victims never recovered their files, even after the criminals received payment.
  • AI is sharpening the phishing and credential theft campaigns that lead to ransomware, not the encryption payloads themselves.
  • Law enforcement actions such as Operation Cronos confirmed that attackers routinely retain stolen data long after receiving payment.
  • Defensive planning, immutable backups, and identity hardening matter more than negotiation tactics once data is stolen.

What the New Proofpoint Data Shows

Technical illustration explaining What the New Proofpoint Data Shows for ransomware re-extortion
What the New Proofpoint Data Shows shows a practical part of ransomware re-extortion.

The Proofpoint survey, published in mid-2026, paints a consistent picture across markets. Paying is common, regret is widespread, and the criminals involved rarely consider the transaction final. Among UK respondents, 58% of organizations hit by a ransomware attack admitted to paying a ransom. Worldwide, the figure sits at 54%, but the regional spread is dramatic, ranging from 19% in Japan to 93% in the United States.

Proofpoint attributes the regional variation to a mix of regulatory pressure, recovery capability, insurance incentives, and cultural norms around negotiation. What stays constant is the underlying dynamic: ransomware creates enough operational pain that a significant share of victims in every market calculate that paying is the cheaper option. Once that calculation is made, the attackers know exactly how motivated the victim is, and they use that information.

For British organizations, the repeat extortion rate of 22% is meaningfully lower than the global average of 37%, but it is still far from rare. One in five organizations that paid found themselves back at the negotiating table, or back at the receiving end of a public leak threat, after the original payment cleared.

Why Repeat Extortion Happens

Ransomware operators rarely rely on a single pressure lever. The modern playbook is double extortion, combining file encryption with the threat of publishing stolen data. In some cases, triple extortion layers in distributed denial-of-service pressure or direct harassment of customers and partners. When a victim pays to suppress the leak and obtain a decryptor, the criminal group still holds the original data set. There is no technical reason for them to delete it, and every financial reason to keep it.

Operation Cronos, the law enforcement operation that dismantled the LockBit infrastructure, provided hard evidence of what had long been suspected. Seized infrastructure showed that victims whose data was supposedly deleted in exchange for payment were still catalogued in the attackers' internal systems. The takedown did not just remove a leading ransomware brand; it undermined the assumption that paying returns the situation to the starting line.

There are also cases where the promised decryptor never works at all. Earlier in 2026, Nitrogen's ESXi ransomware victims reported that a coding error in the operator's decryptor left some environments unable to fully restore access. Around 2% of all victims who paid in the Proofpoint survey said they never recovered their files. Attackers do not need to be reliable to keep the money flowing. They only need victims to be desperate.

Regional Payment Patterns at a Glance

The table below summarizes the headline numbers from the Proofpoint survey. It is useful for understanding how peer organizations behave under pressure, and for benchmarking your own incident response plan against realistic expectations.

MarketOrganizations That Paid a RansomRepeat Extortion Rate (Paid Victims)
United Kingdom58%22%
Global Average54%37%
United States93%Not separately broken out
Japan19%Not separately broken out

The Role of AI in Getting In the Door

Artificial intelligence is not yet driving the encryption stage of ransomware itself, but it has materially improved the stages that lead up to it. Among UK security practitioners surveyed, 65% said AI had sharpened the attacks that precede ransomware and extortion, particularly malicious links, business email compromise, malicious attachments, and credential harvesting.

Cleaner phishing lures, more convincing impersonation of senior staff, and faster internal reconnaissance once credentials are stolen all shorten the time between initial contact and full domain compromise. As Ryan Kalember of Proofpoint summarized, organizations that keep treating ransomware as an endpoint or backup problem are missing where these attacks actually begin: people, identities, and trusted communications. For hosting customers, that means defending the inbox and the admin panel with the same seriousness as the network perimeter.

Why Payment Rarely Restores Security

There are several structural reasons why paying a ransom does not return the organization to its pre-incident state. First, the attacker retains the stolen data set, which can be sold, republished, or used for a second extortion attempt months later. Second, the decryptor may be unreliable, slow, or incomplete, and the criminal has no incentive to provide meaningful support. Third, the payment itself marks the organization as willing to pay, which is valuable intelligence inside criminal forums. Fourth, regulatory and contractual obligations around data breach disclosure do not disappear because the ransom was settled.

For website owners running business-critical apps on SiteCountry cloud hosting, the practical takeaway is that defense in depth, not negotiation, is the only durable response. Backups need to be immutable, off-site, and tested. Admin credentials need to be protected behind phishing-resistant authentication. And every member of the team needs to be treated as part of the security perimeter, because AI-assisted phishing now makes even careful users vulnerable.

Building Resilience Before an Incident

The most effective ransomware response is the one that runs before the attacker gets in. That means documenting the environment, segmenting sensitive data from the public-facing site, and rehearsing the recovery process until it is boring. It also means reviewing policies and expectations through the lens of the SiteCountry Terms of Service and the shared responsibilities that come with managed hosting.

For teams moving between providers or consolidating infrastructure, a structured migration reduces the risk of configuration drift that attackers love to find. The migrating a website from hostinger to SiteCountry manually via files database import guide is a useful reference for keeping credentials, configurations, and file ownership clean during the move, which indirectly reduces the attack surface that ransomware operators look for.

Day to day, the SiteCountry Knowledge Base is a practical place to confirm backup policies, control panel access controls, and incident reporting channels before anything goes wrong. Knowing exactly where to find that information under pressure saves hours during an active incident, and hours are what determine whether a ransomware event becomes a contained disruption or a full operational crisis.

Testing the Plan You Hope You Never Use

Tabletop exercises, restore drills, and offline backup verification are unglamorous, but they are the difference between a managed recovery and a ransom negotiation. Teams that simulate a full encryption event, including the loss of customer-facing dashboards, are far better positioned to refuse payment when the actual incident hits. A clear playbook, signed off by leadership, removes the need to make stressful decisions in the middle of the night.

It also helps to keep up with broader threat trends published on the SiteCountry Blog, where ransomware, phishing, and hosting-related security topics are covered regularly. Awareness of current tactics feeds directly into the realism of the tabletop scenarios you run internally.

Frequently Asked Questions

What is ransomware re-extortion in simple terms?

Re-extortion is when a ransomware group returns to a victim who has already paid, demanding a second payment for the same stolen data. The attackers keep the original data set after the first payment, so they can threaten to publish it again later, sell access to it, or use it as leverage for further demands. The original payment does not protect the victim from this follow-up pressure.

How common is repeat extortion after paying a ransom?

Globally, around 37% of organizations that paid a ransom were extorted again. In the UK specifically, the Proofpoint survey puts that figure at 22%. The exact rate varies by region, sector, and attack group, but the core finding is consistent: paying is not a reliable way to make the threat stop.

Can paying a ransom actually get my files back?

Sometimes, but not always. Around 2% of victims in the Proofpoint survey said they never recovered their files even after paying. Decryptors can be buggy, slow, or incompatible with the affected systems, and criminals have no incentive to provide support once the payment clears. Even when files are technically recovered, the stolen data typically remains in the attacker's hands.

How is AI changing the ransomware threat today?

AI is not yet driving the encryption payload itself in most cases, but it is sharpening the phishing, credential theft, and reconnaissance stages that lead to ransomware. Attackers use AI to craft more convincing emails, impersonate colleagues more effectively, and move faster inside compromised networks. That makes human identity and inbox security more important than ever.

What should my organization do instead of planning to pay?

Focus on resilience before the incident. Maintain immutable, offline-tested backups. Enforce phishing-resistant multi-factor authentication on every admin account. Segment sensitive data from public-facing infrastructure. Rehearse the recovery process so leadership is not making the call to pay under pressure. Document your incident response plan and know exactly where to find it.

Conclusion: A Practical Action Checklist

Repeat extortion is now a standard feature of the ransomware economy, and the Proofpoint data leaves little room for complacency. Use the following checklist to translate the findings into concrete actions for your hosting environment and your wider organization.

  • Confirm that backups are stored offline or in immutable storage, and test a full restore at least quarterly.
  • Audit every admin and SSH account for phishing-resistant multi-factor authentication, and remove any account that does not need it.
  • Segment customer databases, payment systems, and website files so a single compromise cannot reach everything.
  • Run a tabletop exercise that simulates a double extortion event, including the public leak threat and a second demand.
  • Review the shared responsibility model with your hosting provider, including backup scope, access controls, and incident reporting.
  • Train staff to recognize AI-enhanced phishing, especially impersonation of executives and unusual payment requests.
  • Document a formal position on ransom payment, signed off by leadership, so decisions are not improvised during an incident.
  • Keep threat intelligence and response guidance current, so the playbook reflects the way ransomware crews actually operate today.

Paying is a business decision, but the data shows it is rarely a security decision. Build the resilience that removes the need to pay in the first place, and the second extortion attempt becomes a problem you are prepared for, not a crisis you are forced into.