Ransomware victims are increasingly facing a new dilemma: paying a ransom does not guarantee safety from further attacks. Recent research highlights that ransomware crews are returning for repeat extortion, targeting the same organisations after initial payments are made. This troubling trend is particularly visible in the UK, where a significant proportion of targeted companies are being hit again despite having already paid the original demands.
Ransomware Repeat Attacks: What the Latest Proofpoint Data Reveals
According to fresh findings from cybersecurity firm Proofpoint, 58 percent of UK organisations that fall victim to ransomware attacks end up paying the extortionists. However, a staggering 22 percent of those who pay are subsequently re-extorted, facing additional demands from the same or different criminal groups. This data, released in July 2026, underscores a persistent and growing risk for British organisations navigating the ransomware landscape.
The UK figures closely mirror the global picture. Across all surveyed regions, 54 percent of ransomware victims pay up. Although payment rates differ dramatically—ranging from as low as 19 percent in Japan to as high as 93 percent in the United States—the fundamental issue remains unchanged: paying ransom rarely ends the ordeal. The attackers often retain the leverage they gained, including stolen data, decryption keys and the threat of public exposure.
- 58 percent of UK ransomware victims pay ransom demands
- 22 percent of those who pay are hit with repeat extortion
- Globally, 54 percent pay, with regional variation
- 2 percent of paying victims never regain access to their files
Proofpoint’s analysis attributes the varying payment rates to differences in regulatory environments, recovery capabilities, insurance policies and cultural attitudes towards negotiation. Despite these differences, the pressure exerted by ransomware attacks consistently leads a significant share of organisations in every region to pay up, even though this rarely resolves the underlying issue.
Understanding How Attackers Exploit Payment Cycles
When a victim organisation pays a ransomware demand, it is often under the assumption that the attackers will honour their promises: providing a decryption key, deleting stolen data and ceasing further attacks. However, as recent events and law enforcement actions have shown, these assumptions are dangerously misplaced.
Operation Cronos, which targeted the notorious LockBit ransomware group, provided the first concrete evidence that cybercriminals routinely keep victim data even after receiving payment. Before this operation, it was widely suspected but unproven that ransomware gangs retained access to sensitive information post-extortion. The takedown of LockBit not only disrupted a major cybercrime operation but also shattered the illusion that paying a ransom restores the status quo for victims.
Attackers exploit the payment cycle by retaining valuable assets:
- Stolen data, which can be used for further blackmail or sold on criminal marketplaces
- Decryption keys, often withheld or malfunctioning, leaving victims unable to recover files
- Ongoing access to compromised systems, enabling repeated intrusions and demands
Proofpoint’s data revealed that 2 percent of victims who paid a ransom never recovered their files at all. Technical failures and deliberate deceit both play a role. Earlier in 2026, Nitrogen’s ESXi ransomware campaign highlighted this risk when a coding error in the decryptor left victims unable to fully restore operations. This was not an isolated incident. Attackers have little incentive to keep their promises, and many see repeat extortion as a lucrative means to maximise profit from already compromised targets.
AI’s Role: Sharpening the Tools of Ransomware Attackers
Artificial intelligence is rapidly changing the tactics used by ransomware crews. While AI is not yet central to the ransomware payloads themselves, it is making a significant impact in the lead-up to attacks. Proofpoint’s UK data shows that 65 percent of security professionals have observed AI-driven improvements in phishing, business email compromise, malicious attachments and credential harvesting.
AI enables attackers to craft more convincing phishing emails, impersonate trusted contacts with greater accuracy and conduct rapid reconnaissance once inside a corporate network. These advanced techniques increase the likelihood of a successful initial compromise, setting the stage for ransomware deployment.
Key findings on AI and ransomware include:
- AI-enhanced phishing and credential theft is a growing entry point
- Business email compromise campaigns are more convincing than ever
- Faster and more targeted system reconnaissance by attackers
Ryan Kalember, Proofpoint’s chief strategy officer, emphasised that while AI hasn’t fundamentally changed ransomware itself, it has materially improved the preliminary attacks that make successful ransomware campaigns possible. He warned that treating ransomware solely as a technical recovery issue misses the broader point: the majority of attacks begin with compromised identities and trusted communications, not with the ransomware payload itself.
Why This Matters: Implications for UK Organisations
The persistent threat of repeat extortion highlights the need for a shift in how organisations approach ransomware. The evidence is clear: payment cannot be relied on as a risk management strategy. Attackers are not only untrustworthy but are also incentivised to continue exploiting organisations that have demonstrated a willingness to pay.
With AI accelerating the sophistication of pre-ransomware attacks, organisations must prioritise preventative controls around email security, identity protection and the ability to detect and respond to initial intrusions. Building resilience is essential, as is understanding that the threat landscape continues to evolve with criminal innovation and technological advancement.
What Organisations Should Do Now
- Reassess reliance on ransom payments as a contingency
- Invest in layered defences, especially around email and identity
- Review incident response plans for repeat extortion scenarios
- Stay informed on AI-driven attack methods and update training accordingly
Repeat ransomware extortion is a growing risk. Effective defences must focus not just on endpoint recovery, but on preventing attackers from gaining a foothold through people, credentials and trusted communications.
Originally reported by theregister.com.




