Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More?

Every time a ransomware attack makes the news, the advice is almost always the same and that is: don’t pay the criminals.

It sounds like the obvious choice until a business is locked out of its own systems or staff cannot do their jobs and criminals are threatening to publish confidential information. Because of that, many organisations decide paying is the least painful option.

The issue here is that paying often does not bring the attack to an end…

Proofpoint’s new research found that 58% of UK organisations affected by ransomware paid the attackers. Still, 22% of those that handed over the money received another ransom demand. The company’s findings say that today’s ransomware attacks are no longer a one off event because for many victims, they become an ongoing negotiation.

 

Why Are Businesses Paying If There Are No Guarantees?

 

Businesses usually pay because they want the problem to disappear as quickly as possible. They want their systems back online, employees working again and customers looked after.

Criminals know that, and hey also know they have another bargaining chip before they even ask for money.

Proofpoint found that 66% of UK organisations had sensitive data stolen during a ransomware attack. That changes the conversation completely. Even if a business manages to recover its systems, hackers can threaten to leak confidential files unless another payment comes through.

The sis could be seen in Proofpoint’s global research as well. The company surveyed 953 cyber security professionals from 12 different countries and found that 54% of affected organisations paid a ransom and 37% were then asked for more money. Paying, it seems, is no promise that the calls from cyber criminals will stop.

 

How Are Hackers Getting Through The Front Door?

 

Forget the image of someone frantically breaking through digital defences – Many ransomware attacks begin with something much less dramatic.

An email lands in an inbox with a link that looks genuine. A message claims to come from a trusted colleague or supplier and instantly, someone clicks.
 

 
Proofpoint found that phishing emails or other email based social engineering started 24% of ransomware attacks reported by UK organisations. Malicious links were the most common threat, appearing in 40% of incidents. Across the global research, 47% of ransomware attacks began with a malicious link.

AI is making that job much easier for attackers with around 65% of organisations who were affected by ransomware saying AI made the attack more effective.

Employees are also finding it harder to tell the difference between a genuine message and a fake one. In the UK, 24% of organisations said staff did not suspect the attack because it looked authentic, and 31% said users interacted with malicious content. Of all countries surveyed, 40% said employees trusted AI generated attacks because they looked legitimate.

Ryan Kalember, Chief Strategy Officer at Proofpoint, said, “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware. Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

 

Has Ransomware Become A Different Kind Of Crime?

 

The old ransomware tricks were not this complex – criminals locked a company’s files and demanded money to unlock them – but Proofpoint’s research says that is no longer enough for many attackers.

Stealing sensitive information gives criminals another way to make money because they can ask for another payment or threaten to publish confidential files or even sell the stolen data somewhere else. Encryption has become one bit of a way bigger operation.

That is why paying a ransom no longer guarantees the problem is over. A business may regain access to its systems, but if attackers have already copied valuable information, they still have something to bargain with.

Kalember said, “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware. Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

This may be the biggest lesson from Proofpoint’s research for businesses; paying the first ransom does not always buy an ending because in many cases, it just opens the door to the next demand.