🟠 High  |  Source: The Register — Security


A Proofpoint study reveals that over a third of ransomware victims who paid a ransom were subsequently extorted a second time by the same threat actors. In some cases, victims never recovered their files even after paying. This highlights the fundamental unreliability of paying ransoms as a recovery strategy and the growing opportunism of ransomware crews.

Security Architect’s Take: Treat ransom payment as a non-strategy: architect immutable, air-gapped backups (e.g. AWS Backup Vault Lock, Azure immutable blob storage, or GCP Backup and DR with locked vaults) so recovery never depends on attacker cooperation. Pair this with a tested incident response playbook that explicitly rules out payment as a default response.

Original advisory: Greedy ransomware crews return for seconds after victims cough up first extortion payments