A Proofpoint survey of UK organizations hit by ransomware found that 58 percent paid a ransom following an attack — and that 22 percent of those who paid were subsequently extorted again by the same threat actors. The figures, reported by DataBreaches.net, add fresh empirical weight to guidance that authorities have repeated for years: payment does not end the threat.

Why payment fails as a containment strategy

When an organization pays a ransom, it resolves one negotiation but leaves the underlying conditions that made it a target entirely intact. Attackers retain exfiltrated data, retain knowledge of the network architecture they exploited, and — in many documented cases — retain access through secondary backdoors planted before or during the encryption event.

The extortion-on-repeat pattern follows a predictable logic. Once a group confirms that a target has both the willingness and financial capacity to pay, that organization becomes a higher-confidence prospect for a second demand. Payment, in effect, functions as a signal of exploitability rather than a conclusion of the incident.

For healthcare organizations, this dynamic is compounded by the regulatory exposure that follows a breach. Paying a ransom does not extinguish HIPAA breach-notification obligations, does not eliminate the possibility of OCR investigation, and does not restore the trust of affected patients. It adds a financial loss on top of a compliance event that was already unavoidable.

What the second-extortion cycle looks like in practice

Second-extortion attempts typically take one of two forms. In the first, the same group returns weeks or months after the initial payment with a new threat — usually threatening to publish data they withheld from the first negotiation or claiming to have retained deeper access than the victim realized. In the second, a separate criminal group purchases exfiltrated data from the original attacker on dark-web markets and independently approaches the victim with its own demand.

Healthcare organizations are disproportionately represented in both scenarios. Patient records, clinical data, and billing information command premium prices on criminal data markets because of their sensitivity and the leverage they create against covered entities and their patients alike.

Where this lands for independent practices

The survey data shifts the framing for how practice administrators should evaluate ransomware response plans. The relevant question is no longer whether to pay in an acute crisis but whether the organization has invested sufficiently in the controls that make payment a question it never has to answer.

Several preparation areas directly address the repeat-extortion risk:

What this signals about the next 12 months

The repeat-extortion pattern is not new, but the survey's scale — covering a substantial portion of affected UK organizations — gives it broader evidentiary standing than anecdotal incident-response reporting. US-facing threat groups operate from the same economic incentives, and the behavioral pattern observed in UK organizations maps directly onto what US healthcare incident responders have documented domestically.

Law enforcement agencies including the FBI and CISA have consistently advised against payment. The current data suggests that advice is not merely principled but operationally accurate: payment does not reliably terminate attacker engagement with the victim organization. For independent practices weighing response options under pressure, that finding deserves weight before any payment decision is made.