Greedy ransomware crews return for seconds after victims cough up first extortion payments 81%

7/22/2026, 11:49:12 AM

BS Summary: This article contains 21 faulty reasoning types, including Overconfidence Bias, Hasty Generalization, and Confirmation Bias, with Negativity Bias as the most egregious example at 41.6% saturation with 205 hits. Analysis detected 1,139 faulty-reasoning hits from 493 analyzed words, generating a BS Score of 73.6% and a BS Rank of 81% (3,786 of 19,901 articles). This article is worse (more manipulative) than 81.00% of the article peer group.

Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn't mean the crooks leave you alone. 
Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. 
Worse, 22 percent of those who pay get extorted again anyway. 
The UK broadly tracks the global picture: 54 percent of victim organizations paid, though the rate swings sharply by region, from just 19 percent in Japan to 93 percent in the US. 
Cybersecurity biz Proofpoint, which published the data on Wednesday, attributes the regional variation to "a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation." 
"But the core finding holds everywhere: ransomware creates enough pressure that a significant share of organizations in each of the surveyed markets choose to pay." 
UK organizations that paid fared somewhat better than the 37 percent global average for repeat extortion. 
Still, the core lesson stands: paying doesn't reverse an attack. 
You can't trust a criminal's word. 
It just restarts a negotiation where the attacker holds every card, including the data, decryption keys, and the threat of publishing what they've stolen. 
Operation Cronos, law enforcement's LockBit takedown, provided hard proof of what had long been suspected: cybercriminals often retain victim data even after being paid. 
Before Dmitry Khoroshev's cybercrime empire collapsed, this was an assumption, not evidence-based. 
Cronos didn't just shutter the then-leading ransomware gang; it undermined the entire premise that paying restores the status quo. 
Proofpoint found that 2 percent of victims who paid a ransom never recovered their files at all. 
Earlier this year, Nitrogen's ESXi ransomware victims hit a similar wall after a coding error in the decryptor left some unable to fully restore access, and it was far from an isolated case. 
Attackers don't need to hold up their end of the bargain to keep the payments coming. 
The better answer is to build cyber-resilience into the organization itself. 
A word on AI No 2026 security report is complete without AI. 
In the UK, 65 percent of surveyed security practitioners said AI had sharpened the attacks that precede ransomware and extortion, most notably malicious links, business email compromise, malicious attachments, and credential harvesting. 
AI is not yet a key tool in ransomware payloads themselves, despite recent reports suggesting this may soon change. 
However, it is being used for more convincing phishing lures, sharper impersonation attempts, and faster system reconnaissance once attackers are inside a network. 
"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it," said Ryan Kalember, chief strategy officer at Proofpoint. 
"Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale. 
"Organizations that continue treating ransomware as an endpoint or recovery problem are missing where these attacks most frequently begin: people, identities and trusted communications." 
® 
Confirmation Bias
20.9%
Anchoring Bias
6.5%
Availability Heuristic
20.9%
Representativeness Heuristic
19.3%
Hindsight Bias
2.4%
Overconfidence Bias
27%
Framing Effect
5.1%
Loss Aversion
0%
Status Quo Bias
2.2%
Sunk Cost Effect
0%
Optimism Bias
3.2%
Pessimism Bias
3.9%
Negativity Bias
41.6%
Self-Serving Bias
0%
Fundamental Attribution Error
4.9%
Actor-Observer Bias
0%
In-Group Bias
0%
Out-Group Homogeneity Bias
0%
Halo Effect
0%
Horn Effect
0%
Dunning-Kruger Effect
0%
Recency Bias
0%
Primacy Effect
0%
Blind-Spot Bias
0%
Ad Hominem
0%
Straw Man
0%
Appeal to Authority
9.7%
False Dilemma
9.3%
Slippery Slope
0%
Circular Reasoning
0%
Hasty Generalization
26%
Red Herring
0%
Bandwagon
0%
Appeal to Emotion
2.4%
Begging the Question
0%
Post Hoc (False Cause)
5.9%
Tu Quoque
0%
Burden of Proof
0%
Appeal to Nature
0%
Composition/Division
0%
Anecdotal
6.7%
No True Scotsman
0%
Ambiguity (Equivocation)
5.9%
Gambler’s Fallacy
0%
Middle Ground
0%
Personal Incredulity
0%
Special Pleading
0%
Genetic Fallacy
0%
Unattributed Quote
0%
Quote-first Misdirection
0%
Biased Writer Voice
0.2%
Indoctrination
7.1%
Politically Left Leaning Bias
0%
Politically Right Leaning Bias
0%
Attempt to Sell a Product or Service
0%

493 words analyzed.

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.