New survey data confirms what investigators have suspected: paying a ransomware gang rarely buys the closure victims think they are purchasing.

 

What happened

More than one-third of companies that paid a hacker's ransom were later hit with a second extortion demand, according to a survey of 953 companies published this week by security researchers, TechCrunch reported on July 22, 2026. The finding lands on top of years of government warnings against payment, which have mostly argued that ransoms fund the next attack. The survey adds a more immediate reason for reluctance, showing that a payment frequently marks the beginning of a longer relationship with the criminals rather than the end of one. Extortion has shifted from a single transaction, where attackers collected once and moved on, into an operation built on multiple forms of leverage, with stolen data held in reserve under a standing threat of public release.

 

Going deeper

A June 2026 incident at market research firm Klue shows how little a deletion promise is worth. After a hack exposed data belonging to Klue's customers, including several cybersecurity firms, the company struck a deal with the attackers, who claimed to have deleted the stolen material. Klue later conceded that a separate hacking group had swiped a sample of the data, leaving its customers exposed to future extortion attempts from a party that was never part of any agreement. The structure of the criminal economy makes this outcome predictable. Most large ransomware operations run on an affiliate model, where a core group builds the malware and rents it out to independent crews who carry out the intrusions, so stolen data routinely passes through several sets of hands. A deal with one party binds nobody else who touched the files, and nothing verifiable ever confirms that copies were destroyed. Deletion cannot be proven, only promised.

 

What was said

"Some of the data on LockBit's systems belonged to victims who had paid a ransom to the threat actors, evidencing that even when a ransom is paid, it does not guarantee that data will be deleted, despite what the criminals have promised," the United Kingdom's National Crime Agency said in a statement following its February 2024 takedown of the LockBit ransomware operation, as reported by The Record. Investigators found the retained victim data on servers they seized during the operation.

 

In the know

Healthcare has already produced the most expensive example of repeat extortion on record. After a Russian-speaking ransomware gang stole the health and medical data of roughly 192 million people from Change Healthcare in 2024, a dispute broke out between the gang and the affiliate that carried out the intrusion, and Change Healthcare ended up paying separate ransoms to both groups to keep the medical records off the internet. The first payment, reportedly $22 million, went to the core operation, which then vanished without paying its affiliate. The affiliate still held the data and opened its own negotiation. Any healthcare organization weighing a payment should read that sequence carefully, because the party receiving the money and the party holding the files are often not the same, and satisfying one leaves the other fully armed.

 

The big picture

Payment also settles nothing on the regulatory side, which changes the calculation for healthcare organizations in particular. A ransomware incident involving protected health information triggers breach notification obligations whether or not a ransom changes hands, since the law turns on unauthorized access to the data rather than on what the attackers ultimately do with it. Federal agencies including the FBI, the Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services have issued joint advisories on ransomware groups targeting healthcare that consistently discourage payment while pushing organizations toward the controls that make the question moot: tested offline backups, patched remote access infrastructure, and defenses at the email layer where most intrusions begin. Prevention spending has a way of looking expensive right up until the alternative arrives, and Paubox's Hidden Cost of Inaction report found that 73% of healthcare IT leaders expected more email-related breaches ahead, an expectation the repeat-extortion data suggests is well founded for anyone hoping a one-time payment will make the problem go away.

 

FAQs

Does cyber insurance cover a second ransom demand?

It depends on the specific policy and ransom negotiations. Many policies cover a single extortion event and treat follow-on demands tied to the same stolen data as part of the original claim, which may already be exhausted. Some insurers have also added co-insurance requirements or sub-limits for extortion payments, so organizations should review policy language before assuming repeat demands are covered.

 

Is paying a ransom ever illegal in the United States?

It can be. The Treasury Department's Office of Foreign Assets Control has warned that payments to sanctioned individuals, groups, or jurisdictions may violate sanctions law even when the victim does not know who is on the receiving end. Organizations that pay typically route the decision through legal counsel and specialized negotiators partly to manage this exposure.

 

Who should be involved before any payment decision is made?

Legal counsel, the cyber insurer, an experienced incident response firm, and law enforcement, ideally through an existing FBI field office relationship. Involving the FBI early does not obligate any particular course of action, and agents can sometimes provide intelligence about a specific gang's track record of honoring or breaking its promises.

 

How do regulators find out about breaches if a victim pays quietly?

Stolen data has a way of surfacing regardless, through leak sites, resale on criminal forums, or subsequent incidents at the gang itself. Covered entities under HIPAA must report breaches affecting 500 or more individuals within 60 days of discovery, and concealing a known breach exposes the organization to enforcement action considerably worse than the breach itself.

 

What does a tested backup strategy actually involve?

Copies of critical data stored offline or in immutable storage that ransomware cannot reach from the network, combined with regular full restoration drills that measure how long recovery genuinely takes. Backups that exist but have never been restored under time pressure routinely fail during real incidents, which is precisely when the pressure to pay becomes hardest to resist.