Digital Transformation · July 23, 2026
Ransomware Re-Extortion: One-Third of Paying Victims Targeted Again
Over a third of organisations that paid a ransomware demand were subsequently re-extorted by the same attackers, per Proofpoint — and some never recovered their data at all.
What happened
More than a third of organisations that paid a ransomware demand were subsequently targeted for a second extortion attempt by the same threat actors, according to new research published by cybersecurity firm Proofpoint. The finding upends the implicit bargain that paying a ransom buys a clean exit from an attack.
Proofpoint's analysis further found that a portion of victims who paid never recovered their encrypted files at all — meaning they absorbed both the financial cost of the ransom and the operational cost of permanent data loss. The research points to a maturing criminal ecosystem in which ransomware crews treat compliant victims as reliable revenue sources rather than one-time targets.
Why it matters
For customer-experience and service-design leaders, this research reframes ransomware from a pure IT-security problem into a systemic threat to service continuity and customer trust. An organisation that suffers repeated extortion events — or that loses data despite paying — faces compounding disruption: degraded systems, eroded employee confidence, and the near-certain prospect of customers experiencing outages, data-breach notifications, or deteriorating service quality. The behavioural economics here are stark: paying a ransom is a sunk-cost decision dressed up as crisis management, and Proofpoint's data suggests it reliably signals to attackers that the victim is both vulnerable and willing to pay again.
From a service-design perspective, the implications extend to vendor and supply-chain resilience. Many customer-facing failures originate not in a brand's own systems but in a compromised third-party provider. Leaders who have not stress-tested their recovery architecture — or who assume that cyber-insurance and ransom payment constitute a recovery strategy — are, in effect, designing fragility into the customer journey.
By the numbers
- More than one-third of ransomware victims who paid a ransom were subsequently re-extorted by the same attackers, per Proofpoint's findings.
- A measurable share of paying victims never regained access to their encrypted files, sustaining both financial loss and permanent data damage.
The Renascence take
The instinct to pay and move on is entirely human — it is loss aversion and present bias operating under extreme pressure. But Proofpoint's data exposes what behavioural economists would call a "compliance trap": the act of paying does not resolve the underlying vulnerability; it advertises it. Most post-incident reviews focus on what went wrong technically. Far fewer ask the harder service-design question: what does our recovery architecture communicate to an adversary, and what does it communicate to a customer waiting for their service to be restored?
The real CX failure here is not the attack itself — it is the absence of a recovery experience designed around the customer. Organisations that treat ransomware response as purely a security and legal matter are missing the moment when customer trust is most at stake. A customer-obsessed operator should have a rehearsed, human-centred communication and service-restoration playbook that runs in parallel with the technical response — because how you behave under duress is the most honest signal your brand will ever send. Paying twice, or losing data after paying once, is not just a security failure; it is a service-design failure hiding in plain sight.
Sources
This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
More in Digital Transformation
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.