Back to feed

Ransomware Attacks: Why Paying the Ransom is Not the Solution

Authorities warn against paying ransoms in ransomware attacks, as it may lead to further demands and funding for future attacks. A recent study highlights the evolving nature of these threats.

Ransomware Attacks: Why Paying the Ransom is Not the Solution

For years, authorities have cautioned victims of ransomware attacks against paying ransoms. The rationale behind this advice is to avoid incentivizing attackers and preventing them from acquiring fresh funds. A recent study has revealed another critical reason to withhold payment.

Organizations and individuals who fall victim to ransomware should refrain from paying the demanded ransoms. Typically, these payments are sought when victims wish to regain access to their encrypted data or prevent the release of sensitive information on the dark web.

The Case Against Paying Ransom

Authorities and cybersecurity experts consistently advise against ransom payments to avoid encouraging further attacks. Additionally, ransoms are often used to fund future cybercrimes. A report from Proofpoint has unveiled another significant reason for victims to refuse payment: attackers may not be satisfied with a single ransom.

According to a survey conducted among nearly 1,000 security experts across twelve markets, 54% of companies that experienced a successful ransomware attack ended up paying the ransom to regain access to their data. Alarmingly, over one-third of these paying companies (37%) were subsequently asked for additional payments by the same attackers.

The Evolving Nature of Ransomware Attacks

Proofpoint's findings indicate that ransomware incidents have transitioned from one-time events, where attackers restore data access post-payment, to ongoing negotiation processes. After receiving an initial payment, attackers leverage multiple forms of pressure, including continued data encryption, stolen data, and threats of publication.

The report further highlights that malicious links leading to phishing sites or malware downloads are the most common entry points for these attacks, accounting for 47% of incidents.

Training Employees: A Key Defense Strategy

Given these findings, one of the most effective preventive measures is to educate employees about cybersecurity risks, as pointed out by Techradar. Regularly backing up data offline and implementing AI-driven cybersecurity services across the IT infrastructure are also recommended strategies.

Interestingly, the survey revealed that 65% of ransomware victims reported that AI has made these attacks more effective. "AI makes phishing and identity theft more convincing, targeted, and difficult to distinguish from genuine communication," the experts from Proofpoint concluded.