
The old warning about ransomware still holds, but a new report gives it sharper numbers: paying hackers does not necessarily make them go away. Proofpoint’s 2026 AI-Era Ransomware Report says 54 percent of affected organisations paid a ransom, and 37 percent of those payers later faced a second demand.
That finding should make executives uncomfortable because it cuts through one of the quiet assumptions behind ransom payments. Many organisations pay because they believe it buys closure; systems restored, stolen data deleted, business interruption reduced, customers protected. The reality is messier. Once a criminal group knows a victim will pay, the same victim can become a better target.
The Proofpoint survey covered 953 companies and found that ransomware and extortion attacks are no longer a single transaction. Attackers often combine encryption, stolen data, reputational pressure and follow-on demands. That makes the payment decision less like negotiation and more like entering a hostile business relationship.
Proofpoint also says 65 percent of ransomware victims believed AI made the attack more effective, while 47 percent of incidents began with a malicious link. That matters because AI can improve the parts of ransomware that target people: emails, fake documents, voice messages, social engineering scripts and internal-looking communications.
This does not mean every ransomware attack is fully automated by AI. It means attackers are getting better at making malicious activity look normal enough for employees to click, approve, download or respond. A convincing first step is often all the attacker needs to begin credential theft, lateral movement or data exfiltration.
The second demand problem also reflects the rise of data theft as a pressure tool. If attackers steal files before encrypting systems, they can threaten publication even after technical recovery. If they keep copies despite claiming deletion, payment does not guarantee safety. Victims may recover operations and still face legal, regulatory and reputational exposure.
The lesson is not that paying is always impossible. In the real world, boards sometimes face awful trade-offs, especially when healthcare, public services or critical operations are involved. But the Proofpoint data strengthens the case that payment should never be treated as a recovery plan.
Recovery has to be built before the attack. That means offline and tested backups, strong identity controls, segmentation, endpoint visibility, phishing-resistant authentication, clean incident-response roles, legal preparation, cyber-insurance clarity and a communications plan that does not begin after the ransom note arrives.
This is especially relevant for Africa as more public services, banks, telcos and startups move deeper into digital infrastructure. TechBooky recently looked at how Uganda is updating its cybersecurity framework as digital risks rise. The same logic applies across the region: digitisation without resilience gives criminals a bigger surface to exploit.
New defensive ideas are also emerging as attackers begin using AI agents. We recently examined context bombing as a way to turn prompt injection against AI-driven attackers. Experimental ideas like that are useful, but they sit on top of the basics. A company without asset visibility, identity hygiene and reliable backups should not expect clever AI defences to save it.
The message from Proofpoint is blunt and it is that a ransom payment may buy time, but it does not buy trust. The better strategy is to make the organisation harder to enter, harder to move through, harder to extort and faster to restore.