Proofpoint says ransom payments still leave UK victims exposed
Proofpoint survey data found 58% of affected UK organizations paid ransoms, while 22% of payers faced further extortion.
By Renata Fuchs · Policy Reporter
· 3 min read
Proofpoint said Wednesday that 58% of affected UK organizations paid a ransomware demand, and 22% of those that paid were extorted again. The figures add more data to a long-standing warning from authorities and incident responders: payment does not reliably buy recovery, deletion of stolen data, or the end of contact with the attacker.
The UK result broadly follows Proofpoint’s global findings. Across surveyed victim organizations worldwide, 54% paid a ransom. The reported payment rate varied widely by country, from 19% in Japan to 93% in the US.
Proofpoint attributed those differences to “a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation.” The company said the common thread is that ransomware creates enough operational and reputational pressure that a large share of organizations in each surveyed market decide to pay.
For buyers and operators, the uncomfortable point is that payment is not a close-out process. Proofpoint’s data says UK organizations that paid were less likely to be re-extorted than the global average of 37%, but the repeat-demand rate remains material. The attacker still controls the stolen files, the decryption process and the threat to publish data.
Payment does not guarantee recovery
Proofpoint found that 2% of victims that paid a ransom did not recover their files. That small percentage is still a meaningful operational risk for companies treating payment as a last-resort recovery mechanism.
Recent law-enforcement action has also weakened the argument that attackers can be trusted to delete stolen data after receiving money. Operation Cronos, the takedown targeting LockBit, produced evidence that ransomware operators retained victim data after payment, according to the account cited by Proofpoint. Before the collapse of Dmitry Khoroshev’s LockBit operation, that behavior was widely suspected but harder to prove.
Decryption can fail for technical reasons as well as criminal ones. Earlier this year, victims of Nitrogen’s ESXi ransomware ran into recovery problems after a bug in the decryptor prevented some from fully restoring access. Proofpoint cited that case as part of a broader pattern: ransomware crews do not need to deliver a clean recovery experience to keep the extortion model working.
The practical implication is budgetary as much as technical. Organizations that rely on the option to pay are accepting uncertainty around whether files will be restored, whether stolen data will remain private, and whether attackers will return with another demand. Proofpoint’s conclusion is that resilience has to be built before an incident, rather than purchased during one.
AI is sharpening the pre-ransomware stage
Proofpoint also reported that 65% of surveyed UK security practitioners said AI has improved the attacks that often come before ransomware and extortion. The company pointed to malicious links, business email compromise, malicious attachments and credential harvesting.
The company did not present AI as the primary driver inside ransomware payloads themselves, although it noted reports suggesting that may change. Proofpoint’s view is that AI is already useful to attackers in phishing, impersonation and faster reconnaissance after network access has been gained.
“AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it,” said Ryan Kalember, Proofpoint’s chief strategy officer. “Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale.”
Kalember said organizations that treat ransomware mainly as an endpoint or recovery problem are missing where many incidents start: people, identities and trusted communications. That framing is self-serving for an email security vendor, but it matches the numbers Proofpoint published. The ransom note is late in the funnel; the earlier failure is often a message, credential or identity workflow that let the attacker in.
This story draws on original reporting from The Register.