LIVE · cybersecurity feed
Live wire
ransomware

Greedy ransomware crews return for seconds after victims cough up first extortion payments

Some never saw their files again either, infosec biz Proofpoint finds

zeroday.news · 10d ago

A new report indicates that a significant percentage of organizations that pay a ransom demand after a cyberattack are subsequently extorted again, with 22% of UK victims experiencing a second demand. Globally, 54% of victims pay the initial ransom, though this figure varies widely by region, from 19% in Japan to 93% in the United States. The report attributes these regional differences to factors such as regulatory environments, recovery capabilities, insurance incentives, and cultural norms around negotiation.

The findings challenge the notion that paying a ransom guarantees an end to an attack or the restoration of data. Law enforcement's Operation Cronos, which disrupted the LockBit ransomware group, provided concrete evidence that cybercriminals often retain victim data even after receiving payment. This operation undermined the premise that paying a ransom would restore the status quo.

Beyond repeat extortion, the report also highlights that some victims who pay never fully recover their files. Two percent of victims who paid a ransom never regained access to their data. Earlier this year, victims of Nitrogen's ESXi ransomware encountered difficulties restoring access due to a coding error in the decryptor, illustrating that even with payment, full recovery is not assured.

The report emphasizes that attackers are not always compelled to uphold their end of the bargain. The most effective defense against ransomware is building robust cyber-resilience within an organization.

The study also touched on the role of artificial intelligence (AI) in the current threat landscape. In the UK, 65% of surveyed security professionals believe AI has enhanced the effectiveness of attacks that precede ransomware, such as malicious links, business email compromise, malicious attachments, and credential harvesting. While AI is not yet a primary component of ransomware payloads themselves, it is being used to create more convincing phishing lures, improve impersonation attempts, and accelerate system reconnaissance once attackers breach a network.

According to a chief strategy officer at Proofpoint, AI has not fundamentally altered ransomware but has significantly improved the attacks that lead to it. Attackers are leveraging AI to generate highly persuasive phishing emails and credential theft campaigns that exploit human trust on a large scale. The report concludes that organizations that view ransomware solely as an endpoint or recovery issue are overlooking the common starting points of these attacks: people, identities, and trusted communications.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.