TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand

Paul Balo by Paul Balo
July 22, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email

In Brief
  • The old warning about ransomware still holds, but a new report gives it sharper numbers: paying hackers does not necessarily make them go away.
  • Proofpoint’s 2026 AI-Era Ransomware Report says 54 percent of affected organisations paid a ransom, and 37 percent of those payers later faced a second demand.
  • That finding should make executives uncomfortable because it cuts through one of the quiet assumptions behind ransom payments.

The old warning about ransomware still holds, but a new report gives it sharper numbers: paying hackers does not necessarily make them go away. Proofpoint’s 2026 AI-Era Ransomware Report says 54 percent of affected organisations paid a ransom, and 37 percent of those payers later faced a second demand.

That finding should make executives uncomfortable because it cuts through one of the quiet assumptions behind ransom payments. Many organisations pay because they believe it buys closure; systems restored, stolen data deleted, business interruption reduced, customers protected. The reality is messier. Once a criminal group knows a victim will pay, the same victim can become a better target.

The Proofpoint survey covered 953 companies and found that ransomware and extortion attacks are no longer a single transaction. Attackers often combine encryption, stolen data, reputational pressure and follow-on demands. That makes the payment decision less like negotiation and more like entering a hostile business relationship.

Proofpoint also says 65 percent of ransomware victims believed AI made the attack more effective, while 47 percent of incidents began with a malicious link. That matters because AI can improve the parts of ransomware that target people: emails, fake documents, voice messages, social engineering scripts and internal-looking communications.

This does not mean every ransomware attack is fully automated by AI. It means attackers are getting better at making malicious activity look normal enough for employees to click, approve, download or respond. A convincing first step is often all the attacker needs to begin credential theft, lateral movement or data exfiltration.

The second demand problem also reflects the rise of data theft as a pressure tool. If attackers steal files before encrypting systems, they can threaten publication even after technical recovery. If they keep copies despite claiming deletion, payment does not guarantee safety. Victims may recover operations and still face legal, regulatory and reputational exposure.

Also worth reading
OpenAI Says Its Test Models Breached Hugging Face During Cyber Evaluation South Africa Wants SIM Cards To Become Trusted Digital IDs Kenya Restores President Ruto Website After Bitcoin Ransom Hack Hugging Face Says An Agentic AI System Hacked Its Data Pipeline Uganda Launches 2026 Cybersecurity Framework As Digital Risks Rise JadePuffer: The First Fully AI-Powered Ransomware Attack Has Arrived

The lesson is not that paying is always impossible. In the real world, boards sometimes face awful trade-offs, especially when healthcare, public services or critical operations are involved. But the Proofpoint data strengthens the case that payment should never be treated as a recovery plan.

Recovery has to be built before the attack. That means offline and tested backups, strong identity controls, segmentation, endpoint visibility, phishing-resistant authentication, clean incident-response roles, legal preparation, cyber-insurance clarity and a communications plan that does not begin after the ransom note arrives.

This is especially relevant for Africa as more public services, banks, telcos and startups move deeper into digital infrastructure. TechBooky recently looked at how Uganda is updating its cybersecurity framework as digital risks rise. The same logic applies across the region: digitisation without resilience gives criminals a bigger surface to exploit.

New defensive ideas are also emerging as attackers begin using AI agents. We recently examined context bombing as a way to turn prompt injection against AI-driven attackers. Experimental ideas like that are useful, but they sit on top of the basics. A company without asset visibility, identity hygiene and reliable backups should not expect clever AI defences to save it.

The message from Proofpoint is blunt and it is that a ransom payment may buy time, but it does not buy trust. The better strategy is to make the organisation harder to enter, harder to move through, harder to extort and faster to restore.

Related Reading

Explore more TechBooky stories from the latest and category sections below.

Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: ai securitycybersecurityData ExtortionProofpointransomware
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand July 22, 2026
  • M-KOPA Reaches 10 Million Customers As Smartphone Financing Scales July 22, 2026
  • M-PESA Ethiopia And Gebeya Bring AI Tools Into A Mobile Money Mini App July 22, 2026
  • OpenAI’s AI Infrastructure Bill Reportedly Swells To $750B July 22, 2026
  • Samsung And Google Bring Galaxy AI Into Smart Glasses July 22, 2026
  • Samsung Galaxy Watch Ultra2 And Watch9 Push Deeper Into AI Health July 22, 2026
  • Samsung Launches Galaxy Z Fold8 Ultra, Fold8 And Flip8 At Unpacked July 22, 2026
  • Apple Reportedly Plans Klarna-Backed Apple Upgrade Leasing Programme July 22, 2026
  • Chinese AI Models Now Drive Huge US Enterprise Token Usage July 22, 2026
  • OpenAI Says Its Test Models Breached Hugging Face During Cyber Evaluation July 22, 2026
  • Google Launches Gemini 3.6 Flash, Flash-Lite And Flash Cyber Models July 22, 2026
  • Samsung Galaxy Unpacked Today: Fold 8, Flip 8 And The Apple Foldable Pressure July 22, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.