Proofpoint survey: payment rates and regional variation
New data published by Proofpoint on Wednesday lays bare a stubborn truth: many organizations still pay, and paying often does not end the attack. Proofpoint's survey found 54 percent of victim organizations globally paid a ransom. That global figure masks sharp regional swings — from just 19 percent in Japan to a staggering 93 percent in the US — and a UK figure that sits above the global average, with 58 percent of affected UK organizations paying.
Proofpoint attributes the regional differences to "a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation." Regardless of the reason, the company says the central dynamic is consistent: "ransomware creates enough pressure that a significant share of organizations in each of the surveyed markets choose to pay."
Repeat extortion: the second hit after a payment
Paying does not guarantee an end to extortion. Proofpoint reports that 22 percent of UK organizations that paid were extorted again. Globally, repeat extortion averaged 37 percent among organizations that paid, the survey found. The report directly counters the implicit bargain victims often make: handing over cash in exchange for silence or recovery.
Proofpoint also found that 2 percent of victims who paid a ransom never recovered their files at all — a tangible failure of the criminal "bargain" and a reminder that payments do not always translate into operational restoration.
Operation Cronos, LockBit and evidence of retained data
Law enforcement action has supplied hard proof that criminals commonly retain victim data after payments. The takedown known as Operation Cronos, which targeted the LockBit operation, "provided hard proof of what had long been suspected: cybercriminals often retain victim data even after being paid." The report singles out Dmitry Khoroshev's cybercrime empire — which collapsed as part of the operation — as transforming a long-standing assumption into evidence-based fact.
Proofpoint also notes practical failures that demonstrate the same risk: earlier this year, victims of Nitrogen's ESXi ransomware were left unable to fully restore access when a coding error in the decryptor corrupted recovery efforts. That case, the report says, was "far from an isolated case."
AI sharpening the attacks that lead to ransomware
Proofpoint's survey places artificial intelligence squarely in the picture for 2026. In the UK, 65 percent of surveyed security practitioners said AI had sharpened the attacks that precede ransomware and extortion. Those attack vectors include "malicious links, business email compromise, malicious attachments, and credential harvesting," the report states.
Importantly, Proofpoint argues AI is not yet embedded in ransomware payloads themselves. Rather, it is improving the reconnaissance and social-engineering that get attackers inside networks: "Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale," Ryan Kalember said. The upshot, Kalember warns, is that organizations that continue to treat ransomware solely as an endpoint or recovery problem are missing where these attacks most frequently begin: "people, identities and trusted communications."
What this means for technologists, insurers, and affected enterprises
- Technologists and security teams: Proofpoint's findings push toward building cyber‑resilience rather than relying on payment. The report explicitly recommends moving prevention and detection focus upstream to people, identities and communications, where AI-enhanced phishing and impersonation are sharpening initial compromises.
- Insurers and recovery planners: The survey points to "insurance incentive structures" as one factor driving regional payment rates, suggesting that insurers should reassess how policy design affects the likelihood of ransom payments and repeat extortion.
- Affected enterprises and procurement leaders: The combination of repeat extortion, failed decryptors, and evidence that criminals retain data even after payment means organizations should not assume payment restores the status quo. Proofpoint emphasises investing in recovery capability and regulatory compliance as part of the calculus that currently informs regional differences in payment behavior.
The net of Proofpoint's findings is stark and concrete: paying a ransom does not erase the attack, and often it restarts a negotiation in which the attacker "holds every card, including the data, decryption keys, and the threat of publishing what they've stolen." Operation Cronos and the Nitrogen decryptor failures convert the old maxim "you can't trust a criminal's word" into quantifiable outcomes — repeat extortion rates, unrecovered files, and regional behaviors shaped by regulation, insurance, and recovery capacity.
Original story: https://www.theregister.com/security/2026/07/22/over-a-third-of-ransomware-victims-re-extorted-after-paying/5276218




