1. Executive summary
Proofpoint survey data published 22 July 2026 reveals that 58% of affected UK organisations paid a ransom, and 22% of those who paid were extorted again anyway. The global repeat-extortion rate is 37%. The findings corroborate evidence from Operation Cronos — the law-enforcement takedown of LockBit — which demonstrated that ransomware operators routinely retain victim data and decryption keys after payment. Attribution to LockBit is noted in the source material; however, as no MITRE ATT&CK profile exists for this actor in the verified reference data, attribution remains unconfirmed. For EMEA financial services, the core risk is that payment does not terminate the incident: attackers retain leverage to re-extort, and 2% of paying victims never recovered their files at all.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The advisory describes an industry-wide threat trend and survey findings rather than a specific ICT-related incident at a regulated entity. The general obligation to manage cyber threats applies, but no distinctive fact in this item triggers a specific article beyond what would be true of any security advisory.
3. Technical analysis & attack chain
This item is a strategic/trend piece based on Proofpoint survey data and law-enforcement outcomes. No specific technical attack chain, CVE, payload, or victim environment is described. The following findings are established from the source material:
Repeat extortion mechanism. The core finding is that paying a ransom does not result in attackers deleting stolen data or relinquishing leverage. Attackers retain victim data, decryption keys, and the threat of publication. Re-extortion follows because the attacker retains all cards: the data, the keys, and the publication threat. The victim's payment simply restarts a negotiation in which the attacker holds structural advantage.
Operation Cronos evidence. The LockBit takedown provided hard evidence — previously only assumed — that cybercriminals retain victim data after payment. The source names Dmitry Khoroshev in connection with the LockBit operation. Attribution to LockBit is unconfirmed in the verified reference data (no MITRE ATT&CK profile available).
Decryptor failure. Two distinct failure modes are documented:
- 2% of victims who paid a ransom never recovered their files at all (Proofpoint survey).
- Nitrogen ESXi ransomware victims were unable to fully restore access due to a coding error in the decryptor. The source describes this as "far from an isolated case."
AI as an enabler of pre-ransomware activity. 65% of surveyed UK security practitioners reported that AI had sharpened attacks preceding ransomware — specifically malicious links, business email compromise, malicious attachments, and credential harvesting. AI is described as improving phishing lures, impersonation attempts, and post-intrusion system reconnaissance. AI is not yet reported as a component of ransomware payloads themselves.
Regional payment rates. Payment rates vary sharply: 93% in the US, 58% in the UK (broadly tracking the 54% global average), and 19% in Japan. Proofpoint attributes this to regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation.
Confidence caveat: All quantitative findings are single-sourced to the Proofpoint survey as reported by The Register and DataBreaches.net. No independent corroboration of the survey methodology or dataset is available in the provided sources. Verify before using these figures in board-level reporting.
4. Mitigation & containment
This item implicates process controls — payment decision-making, recovery validation, and retrospective fraud review — rather than technical containment of a specific vulnerability.
P1 — within 24h
- Review and update ransomware payment decision frameworks. Explicitly document that payment does not guarantee data recovery or deletion. Incorporate the 37% global re-extortion rate and 2% total recovery failure rate into risk acceptance documentation for any payment decision.
- Ensure incident response playbooks treat post-payment as a continued active incident — not a closed one — with ongoing monitoring for data publication, re-contact from attackers, and evidence of retained data appearing in leak sites.
P2 — within 72h
- Validate all decryptors in an isolated test environment before running against production systems. The Nitrogen ESXi decryptor failure demonstrates that attacker-provided tools can contain coding errors that prevent full restoration.
- If a payment has been made in a prior incident, conduct a retrospective assessment: assume stolen data is still held by the attacker. Monitor criminal leak sites, dark-web marketplaces, and credential dumps for organisational data.
P3 — within 7 days
- Strengthen controls against the AI-enhanced initial-access vectors identified in the survey: malicious links, BEC, malicious attachments, and credential harvesting. Prioritise email security gateway tuning, anti-phishing training, and MFA enforcement on all externally facing authentication surfaces.
- Brief incident response teams and legal counsel on the re-extortion risk so that payment negotiations account for the probability of a second extortion demand.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Re-contact from ransomware actors demanding a second payment after initial ransom was paid | Email, TOX/Session messaging, leak-site portals | High — corroborated by survey data and Operation Cronos findings |
| Stolen organisational data appearing on leak sites after payment was made | Criminal leak sites, dark-web monitoring feeds | High — Operation Cronos provided hard evidence |
| Decryptor provided by attacker fails to fully restore file access | Endpoint logs, backup recovery validation | Medium — single-sourced to survey data and one named Nitrogen ESXi case |
| AI-enhanced phishing lures showing improved impersonation quality and reconnaissance-driven targeting | Email security gateway, SOAR phishing playbooks | Medium — based on practitioner perception survey, not technical artefacts |
6. Detection
Insufficient indicators to author detection rules. The source material describes behavioural patterns and survey findings but contains no file hashes, distinctive strings, command-line artefacts, mutex names, registry keys, or network signatures from which to build YARA or Sigma rules.
7. Sources
- The Register — "Greedy ransomware crews return for seconds after victims cough up first extortion payments" — https://www.theregister.com/security/2026/07/22/over-a-third-of-ransomware-victims-re-extorted-after-paying/5276218 — 2026-07-22
- DataBreaches.net — "Greedy ransomware crews return for seconds after victims cough up first extortion payments" — https://databreaches.net/2026/07/22/greedy-ransomware-crews-return-for-seconds-after-victims-cough-up-first-extortion-payments/ — 2026-07-22
8. Adverse Trace position
This advisory does not describe a new vulnerability or active campaign requiring immediate technical containment. Its value is strategic: the Proofpoint data and Operation Cronos evidence together dismantle the assumption that ransom payment resolves the incident. For EMEA financial services, the practical implication is that payment decisions must be framed as risk transfers with a high probability of failure — 37% re-extortion globally, 2% total non-recovery — not as incident closure. LockBit attribution is unconfirmed in the verified reference data. All quantitative findings are single-sourced to the Proofpoint survey; we will update this advisory if independent corroboration becomes available. Clients should immediately review payment decision frameworks and post-payment monitoring procedures.
Published via PulseTrace — Adverse Trace threat intelligence.