Companies are still paying ransoms to cyber criminals despite official advice
A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
Six-in-ten ransomware victims are still paying up despite official advice not to do so.
That's according to research from security firm Proofpoint, which found that 58% of UK organizations hit by a ransomware attack agreed to pay ransoms.
Crucially, Proofpoint found they weren’t rewarded for bowing to cyber criminal demands. Nearly one-quarter (22%) who did pay were then hit with a second extortion demand.
The study from Proofpoint comes amidst growing calls to play hard ball with ransomware criminals by authorities. The UK's National Cyber Security Centre (NCSC), for example, advises against paying ransoms, warning that it encourages further attacks and may not lead to the return of data.
Despite that being the official advice for many years, plenty of companies pay criminals when faced with ransomware disruption to their business operations.
Security firm Trellix surveyed CISOs whose employers had been the target of ransomware attacks, finding in each instance they decided it was worth paying — with a third paying between $5 million and $15 million.
Those results were echoed by research from Cohesity that showed that while 94% of companies in the UK say they have a policy not to pay out in a ransomware attack, 97% still do.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The case for ransom bans
This disconnect has led to debate over banning ransomware payments, with the UK government saying last year it was considering forbidding public organizations from paying ransoms.
These proposals follow serious incidents at NHS bodies, the British Library, and Royal Mail in recent years.
The government already bans ransomware payments made by its own departments; a wider ban was backed by the government, but has yet to be brought into force.
That included a provision for mandatory reporting of ransomware payments for private companies not covered by the ban. One challenge is enforcement, as fines or other punishments for paying ransoms could risk further victimizing companies.
Evolving techniques raise the stakes
Elsewhere in the study, Proofpoint found new tactics are exacerbating the situation for enterprises.
Ransomware techniques have shifted away from data encryption to outright data theft – and that means companies can expect that data to be used for follow-up attacks or sold on criminal marketplaces.
The result here is that this extends the initial attack and impact for victims, according to Proofpoint.
The rise of AI has also made ransomware more effective, according to two-thirds of companies that faced an attack, particularly in terms of initial compromise.
"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it," said Ryan Kalember, chief strategy officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale."
Hackers are using AI to write better phishing messages and to better hide their attacks, with 31% of those polled said staff didn't suspect anything was wrong when they interacted with malicious content.
Around one-quarter (24%) said attacks succeeded because they appeared to be authentic communications.
The Proofpoint survey found that malicious links remained the most common threat at 40%, followed by compromised email at 35% and credential harvesting at 32%.
"Organizations that continue treating ransomware as an endpoint or recovery problem are missing where these attacks most frequently begin: people, identities and trusted communications," added Kalember.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Nebula appoints Rob Kittler to drive UK partner recruitmentNews The former Gamma executive will lead the communications vendor's reseller and MSP acquisition strategy
-
Google Cloud's record results can't quiet concerns on AI spending and model release timelinesNews Sundar Pichai defended the cost of AI rollouts and delays to frontier models following quarterly results
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti