Close Menu
    Facebook X (Twitter) Instagram
    Tuesday, July 28
    • Home
    • About Us
    • Contact Us
    • Submit Your Story
    • Terms of Use
    • Privacy Policy
    Facebook X (Twitter) Instagram
    Fortune Herald
    • Business
    • Finance
    • Politics
    • Lifestyle
    • Technology
    • Property
    • Business Guides
      • Guide To Writing a Business Plan UK
      • Guide to Writing a Marketing Campaign Plan
      • Guide to PR Tips for Small Business
      • Guide to Networking Ideas for Small Business
      • Guide to Bounce Rate Google Analyitics
    Fortune Herald
    Home»Business»Ransomware Re-Extortion Risk Climbs as Over a Third of Paying Firms Face Second Demands
    ransomware re-extortion risk
    Business

    Ransomware Re-Extortion Risk Climbs as Over a Third of Paying Firms Face Second Demands

    Funke AdeyemiBy Funke Adeyemi28/07/2026No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new survey of nearly a thousand organisations has put the ransomware re-extortion risk in stark relief: pay a criminal gang once, and the odds of a second demand are disturbingly high. Cybersecurity company Proofpoint surveyed 953 full-time security professionals across 20 industries and 12 countries between March and April 2026, and found that more than one-third of organisations that paid a ransom were subsequently hit with a second extortion demand.

    The headline figure is striking enough. The context behind it is worse. More than half (54%) of all organisations affected by ransomware paid up, despite years of law enforcement guidance to the contrary. Once that payment is made, the data suggests, the target becomes a proven source of revenue.

    The Ransomware Re-Extortion Risk by Country

    The willingness to pay varies sharply by geography, according to Cybersecurity Insiders, which reported on Proofpoint’s findings. In the United States, more than 93% of affected organisations chose to pay, compared with roughly 19% in Japan. The UK sits in the middle: 58% of surveyed British businesses admitted paying, and more than 22% of those reported being extorted a further two or three times after their first payment.

    Proofpoint also found that 65% of ransomware-hit organisations said artificial intelligence had made attacks more effective, a figure that adds an accelerant to an already troubling trend. The survey spans the US, UK, France, Germany, Italy, Spain, the UAE, Australia, Japan, Singapore, India, and Brazil.

    The findings reinforce what security researchers have argued for years: ransomware gangs have no structural incentive to honour their side of any deal. Payment does not buy silence, and it certainly does not guarantee that stolen data will be destroyed.

    When the Promise to Delete Data Is Worth Nothing

    Two recent cases illustrate the problem in detail. The first involves Klue, a market research firm. Anomalous activity was detected on 11 June 2026, unauthorised access confirmed on 12 June, and the breach disclosed publicly on 15 June. The attackers had used a compromised credential from a 2022 pilot programme that had been left unrevoked for roughly four years, then leveraged it to harvest OAuth tokens granting access to customer data held in third-party platforms, including Salesforce.

    Roughly 195 to 200 companies had data held inside Klue’s systems, according to TechCrunch. As of late June 2026, only around 15 had publicly confirmed an impact. Among those whose Salesforce environments were accessed, Field Effect confirmed, were Recorded Future, Tanium, Jamf, and Huntress. Klue struck a deal and the hackers claimed to have deleted the data. A separate group then surfaced with a sample of that same stolen data, proof that the deletion promise had not held.

    Huntress, in its own breach investigation post, confirmed that the data copied from its Salesforce account included business contacts, price quotes, and sales-related messaging. No threat intelligence data, passwords, payment card information, or customer credentials were among the compromised material.

    The second case is larger by several orders of magnitude. The Change Healthcare ransomware attack was detected on 21 February 2024, when the company’s systems, which process 15 billion healthcare transactions per year and handle roughly half of all US medical claims, were taken offline. The attackers, the ALPHV/BlackCat gang, had accessed the network through a Citrix portal that lacked multi-factor authentication.

    ALPHV/BlackCat claimed to have stolen 6TB of data, including patient Social Security numbers, medical records, data on active military personnel, payment details, and insurance records. The breach ultimately affected 190 million patient records, according to HIPAA Journal, making it more than twice the size of the previous largest healthcare data breach in US history. (The original report cited 192 million; HIPAA Journal’s detailed analysis puts the figure at 190 million.)

    Blockchain analysis identified a transfer of approximately $22 million in Bitcoin to an ALPHV-associated wallet on 1 March 2024. ALPHV then pulled an exit scam, keeping the payment without passing any share to the affiliate that had actually conducted the attack. That affiliate subsequently found a new partner. On approximately 16 April 2024, a second group, RansomHub, issued its own extortion demand to Change Healthcare, claiming to hold the stolen data and threatening to sell it to the highest bidder, according to Hyperproof. The RH-ISAC had earlier documented ALPHV’s initial claim of responsibility in detail.

    UK law enforcement made the same point in starker terms during the 2024 takedown of the LockBit gang. Police found victims’ stolen data still sitting on LockBit’s servers long after those victims had paid. The ransomware re-extortion risk, in other words, does not expire with the first payment.

    Proofpoint’s survey suggests that corporate behaviour has not yet caught up with that reality. With more than nine in ten US organisations paying when attacked, and AI now accelerating the pace and effectiveness of attacks, the gap between what security researchers advise and what finance committees actually authorise under pressure remains the most exploitable vulnerability in the system.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Funke Adeyemi

    Funke Adeyemi spent a decade in corporate banking and fintech before moving to business journalism. She started in trade finance at a major UK bank, moved to a payments company scaling into African markets, and spent her last role leading partnerships at a cross-border remittance platform. She writes about business strategy, fintech, digital banking, and the corporate news that moves markets. She is interested in how companies actually make money rather than how they describe making money in investor presentations. Funke lives in South London. She reads earnings calls the way other people listen to podcasts, and finds them about as reliable.

    Related Posts

    Glow Endpoint Security Startup Raises $180m at $1.2bn Unicorn Valuation

    28/07/2026

    Synthesia Launches Roleplay Sessions to Turn AI Training Into Performance Data

    27/07/2026

    Anthropic Physical Intelligence Acquisition Talks Expose a Robotics Arms Race

    27/07/2026
    Leave A Reply Cancel Reply

    Fortune Herald Logo

    Connect with us

    FortuneHerald Logo

    Home   About Us   Contact Us   Submit Your Story   Terms of Use   Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.