UK ransomware victims pay 58%, then 22% get hit again anyway, Proofpoint finds
Paying stops nothing, and AI is making the early attacks cheaper, faster, and more convincing.

Proofpoint data shows 58% of extorted organizations in the UK pay their ransom, but 22% of those payers face extortion again. Decision-makers should treat ransomware payments as temporary triage, not a resolution plan, because repeat extortion and failed recovery are real.
If you are still treating ransomware as a “pay and move on” problem, Proofpoint’s new data should land like a brick. In the UK, 58% of extorted organizations pay their ransom. And here is the part that breaks the comforting narrative: 22% of those organizations get extorted again anyway.
This is not theory. It is the pattern the market is already living with. Proofpoint published the findings on Wednesday, and it comes with a blunt implication for boards and executives: paying does not mean the crooks leave you alone. The headline lesson is simple and brutal, ransomware creates enough pressure that a significant share of organizations in each surveyed market choose to pay, even though the “exit” rarely happens after the first payment.
Zoom out beyond the UK and the same core story holds, even if the numbers vary wildly by region. Proofpoint reports a global average where 54% of victims pay, with sharp swings from just 19% in Japan to 93% in the US. Proofpoint attributes the differences to “a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation.” In other words, this is not purely a criminal strategy and it is not purely victim behavior either. It is incentives, capability, and decision culture all colliding under deadline pressure.
The UK data also shows that repeat extortion is a lived reality. UK organizations that pay do fare somewhat better than the 37% global average on repeat extortion, but “somewhat better” is not “safe.” If 22% of UK payers get extorted again anyway, then the first negotiation is not a conclusion, it is a checkpoint. The attacker keeps leverage because they control the data, the decryption keys, and the threat of publishing what was stolen. Paying restarts a negotiation where the criminal still holds the cards, which is why “you can’t trust a criminal’s word” is not just morality. It is operational reality.
Proofpoint also points to earlier hard evidence that many practitioners had suspected for years: attackers often retain victim data even after being paid. Operation Cronos, also known as law enforcement’s LockBit takedown, was the first hard proof of what had long been suspected. The Register’s source frames this as a premise-shift. Before the takedown of Dmitry Khoroshev’s cybercrime empire, the retention of victim data was an assumption, not evidence-based. Operation Cronos did not just shutter a then-leading ransomware gang, it undermined the idea that paying restores the status quo.
The consequences extend beyond repeat negotiations. Proofpoint found that 2% of victims who paid a ransom never recovered their files at all. That is a small percentage until it is your company, because “paid” does not equal “recoverable.” Earlier this year, Nitrogen’s ESXi ransomware victims hit a similar wall after a coding error in the decryptor, leaving some unable to fully restore access. The key point for executives is that attackers do not need to follow through to keep the payments flowing. They only need to maintain pressure, because the victim organization is stuck in a trust gap with high operational stakes.
So where should attention go? The source lands on a familiar but often underfunded answer: the only real defense is building cyber-resilience into the organization itself. That means treating ransomware as a disruption and recovery problem you can engineer for, not an interruption you can buy your way out of. Boards and executives typically focus on end-state outcomes, “Will we be able to decrypt?” The data here suggests a broader framing: reduce the blast radius of extortion, improve recovery capability before an incident, and design decision processes that do not collapse under attacker timelines.
Finally, the source adds the 2026 AI wrinkle, because attackers are upgrading the parts that get victims to click, open, or hand over credentials. In the UK, 65% of surveyed security practitioners said AI has sharpened the attacks that precede ransomware and extortion, “most notably malicious links, business email compromise, malicious attachments, and credential harvesting.” AI is not yet a key tool in ransomware payloads themselves, the source notes, despite recent reports suggesting it may soon change. But it is being used for more convincing phishing lures, sharper impersonation attempts, and faster system reconnaissance once attackers are inside a network.
Ryan Kalember, chief strategy officer at Proofpoint, is quoted in the source with the clearest strategic takeaway: “AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it.” Organizations that keep treating ransomware as an endpoint or recovery problem are missing where the threat starts, “people, identities and trusted communications.” If payments do not end the story, and AI is accelerating the pre-story, then resilience stops being a security slogan and starts looking like budget, process, and culture.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Anthropic’s Levant Alpöge cracks the Jacobian conjecture after 87 years
A Harvard valedictorian used Claude to hit a 1939 breakthrough, but the missing “why” is the real problem.

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.

