Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

Ransomware payments fail to prevent repeat attacks, new data shows

  • What: Ransomware payments fail to prevent repeat attacks
  • Impact: 58% of UK organizations pay ransoms but face repeated extortion
Read Full Article →

Ransomware Ransomware payments fail to prevent repeat attacks, new data shows July 23, 2026 Share By SC Staff As outlined in The Register, new data from Proofpoint revealed that a significant portion of organizations in the UK continue to pay ransom demands, despite evidence that doing so does not guarantee an end to extortion or the recovery of data. This trend persists even as law enforcement efforts, like Operation Cronos, aim to dismantle ransomware operations. Proofpoint's findings indicate that 58% of extorted organizations in Britain pay ransoms, with a concerning 22% of these victims facing subsequent extortion attempts. Globally, 54% of victims pay, though regional variations exist. The data suggests that paying criminals does not restore the status quo, as attackers may still retain stolen data or fail to provide working decryption keys. Operation Cronos, which targeted the LockBit ransomware gang, provided concrete evidence that cybercriminals often keep victim data even after payment. Furthermore, some victims who pay never recover their files, sometimes due to coding errors in decryption tools. The report highlights that AI is increasingly being used to enhance the initial stages of ransomware attacks, such as creating more convincing phishing emails and improving reconnaissance, rather than directly within the ransomware payload itself. Experts emphasize that focusing on human vulnerabilities, identities, and trusted communications is crucial for building cyber-resilience, as ransomware is often preceded by attacks targeting these areas. Source: The Register An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Malware TrickBot variant uses DNS tunneling for command and control SC Staff July 22, 2026 This TrickBot variant, detailed in research by Fortinet's FortiGuard Labs, utilizes a modular architecture but features a redesigned transport layer. Ransomware New ransomware group uses printers to deliver ransom notes SC Staff July 22, 2026 The newly identified group, "XEntry Team," is reportedly behind these attacks. Ransomware Stadler Rail refuses to pay $12.3 million ransom after ransomware attack SC Staff July 22, 2026 The incident, which occurred in mid-July, involved the theft of non-security-relevant technical information from a supplier. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article