If you pay a ransom to a hacker, they will likely come back for more


Governments have long been wary of paying the ransom demanded by hackers, arguing that doing so only allows them to do so. Criminals benefit from their cyber attacks And financing the next stage. There’s also another reason: hackers are less likely to leave you alone if you pay once, and many will come back demanding more.

In a report published on Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and Found More than a third of the companies that paid the hacker’s ransom were subjected to a second extortion request. The findings confirm the long-standing understanding among security researchers and network advocates that it is impossible to negotiate in good faith with an extortion racket because there is no incentive for the other side to actually withdraw.

Proofpoint data shows that ransomware and extortion attacks have evolved from a single transaction where hackers get their money once and then move on, to an effort that uses multiple forms of leverage, such as holding stolen data under threat of making it public.

While hackers have claimed in the past that they will delete or destroy a victim’s stolen data, past incidents have shown that this is not the case.

Last month, a hack was revealed at market research company Klue Data about its customersincluding many cybersecurity companies. The company said it struck a deal with the hackers, who claimed to have deleted the data, but the company later admitted that a separate hacking group had compromised a sample of the company’s stolen data, leaving its customers vulnerable. Possible blackmail requests in the future.

A similar situation occurred at Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, about 192 million people. Amidst a dispute between hackers and their affiliates (often criminal groups). Subcontracting out attacks), Change Healthcare paid a separate ransom For both sets of criminals to keep sensitive medical data off the Internet.

Security researchers have long suspected that ransomware gangs and extortion rackets would keep a victim’s stolen data, even after payment is made. UK law enforcement confirmed this while targeting takedown efforts The prolific LockBit Ransomware gang in 2024. Police said they found stolen victim data stored on LockBit servers long after the ransom was paid.

When you make a purchase through the links in our articles, We may earn a small commission. This does not affect our editorial independence.

Leave a Reply

Your email address will not be published. Required fields are marked *