A new Proofpoint report shows that ransomware is increasingly becoming a repeat-extortion business, not a one-time payoff event. According to the AI-Era Ransomware Report 2026, 37% of organizations that paid ransom once were attacked again, often without ever fully escaping the threat.
The findings are a blunt reminder that paying attackers rarely ends the problem. In many cases, it simply gives criminals more incentive to return.
Key Details
Proofpoint says criminal groups commonly keep backdoors open, retain stolen data, and use that leverage for follow-up demands. The report also notes that 65% of affected organizations believe AI has made attacks more effective, rising to 81% in the United States.
The most common intrusion methods were:
- Malicious links, at 47%.
- Infected attachments, at 46%.
- Stolen credentials, at 36%.
- Compromised business email, at 35%.
The report also found that 40% of security failures occurred because employees believed AI-generated phishing messages were legitimate. In addition, one-third of existing email security systems failed to detect the first attack.
Technical Analysis
The modern ransomware model is no longer just about encryption. It is about access, persistence, data theft, and repeated pressure. Attackers steal sensitive data first, then use the threat of exposure to force payment or additional payment later.
AI amplifies that model by making phishing and impersonation more convincing. That improves initial compromise rates and helps attackers scale their operations faster. It also makes social engineering cheaper and more adaptive.
Proofpoint’s findings suggest that criminals are not deleting stolen data after payment. Instead, they often keep it as a reusable pressure point. That turns one breach into a recurring extortion campaign.
Why It Matters
The regional payment data is especially striking. In the United States, 93% of affected organizations chose to pay. In the United Kingdom, the figure was 58%, compared with 54% globally.
But payment does not guarantee recovery:
- 2% of victims worldwide never recovered their files.
- In the UK, 22% of paying victims were extorted again.
- In 66% of cases, data had been stolen during the attack.
That means companies may be paying for downtime reduction, only to face a second invoice later. The real cost is not only the ransom itself, but the disruption, legal exposure, and repeated operational damage that follows.
Expert Recommendations
Organizations should assume ransomware is now a data-theft and coercion problem as much as a malware problem. The best defense is reducing the chance of first access and limiting the attacker’s ability to stay inside.
Recommended actions:
- Strengthen email security and user training against AI-generated phishing.
- Enforce MFA everywhere possible, especially for email and remote access.
- Lock down stolen-credential exposure with password hygiene and access review.
- Segment critical systems to slow lateral movement.
- Maintain offline, tested backups.
- Monitor for data exfiltration, not just encryption events.
- Create an incident response plan that assumes repeat extortion.
Security teams should also remember that paying once does not end the relationship with the attacker.
Industry Context
The report aligns with earlier law-enforcement findings, including the LockBit takedown, which showed that gangs often retain victim data even after promising deletion. That reinforces the point that ransomware groups are not trustworthy counterparties.
It also fits a broader trend in which attackers increasingly combine malware, identity theft, and social engineering into one campaign. AI lowers the cost of that complexity and helps make the first message look real enough to work.
The message for defenders is simple: prevention, detection, and recovery all matter, but payment is not a strategy.
Conclusion
Proofpoint’s report shows that ransomware is increasingly a repeat-extortion cycle powered by AI, stolen credentials, and data theft. Organizations that pay may buy time, but they do not buy safety.
FAQ SECTION
What does the Proofpoint report say?
It says 37% of organizations that paid ransomware once were attacked again, and AI has made attacks more effective.
Why are repeat attacks happening?
Attackers often keep stolen data, backdoors, or access paths open so they can demand more money later.
How does AI change ransomware?
AI helps attackers craft more convincing phishing, social engineering, and business email compromise campaigns.
Does paying ransom guarantee recovery?
No. Some victims never recover files, and others are attacked again after payment.
What is the most common initial attack method?
Malicious links and infected attachments were the most common entry points in the report.