Among surveyed organisations that paid after a ransomware incident, 37% received a second demand for money, according to Proofpoint research.
The company surveyed 953 cybersecurity professionals across 12 countries in March and April 2026. The organisations represented by 803 respondents had experienced ransomware, and the main findings were calculated from that affected group.
Fifty-four per cent of affected organisations paid. One payment restored access for 56% of payers, while almost 2% transferred money but still failed to regain access to their systems.
About two-thirds of affected organisations reported data theft. The report says extortion increasingly combines encryption, stolen information and sustained pressure on an organisation.
In addition, 65% of respondents at affected organisations said artificial intelligence had made attacks more effective. The figures reflect survey responses and do not show that payment inevitably causes another attack: the measured outcome was a repeat ransom demand.








