Some never saw their files again either, infosec biz Proofpoint finds

A new report indicates that a significant percentage of organizations that pay a ransom demand after a cyberattack are subsequently extorted again, with 22% of UK victims experiencing a second demand. Globally, 54% of victims pay the initial ransom, though this figure varies widely by region, from 19% in Japan to 93% in the United States. The report attributes these regional differences to factors such as regulatory environments, recovery capabilities, insurance incentives, and cultural norms around negotiation.
The findings challenge the notion that paying a ransom guarantees an end to an attack or the restoration of data. Law enforcement's Operation Cronos, which disrupted the LockBit ransomware group, provided concrete evidence that cybercriminals often retain victim data even after receiving payment. This operation undermined the premise that paying a ransom would restore the status quo.
Beyond repeat extortion, the report also highlights that some victims who pay never fully recover their files. Two percent of victims who paid a ransom never regained access to their data. Earlier this year, victims of Nitrogen's ESXi ransomware encountered difficulties restoring access due to a coding error in the decryptor, illustrating that even with payment, full recovery is not assured.
The report emphasizes that attackers are not always compelled to uphold their end of the bargain. The most effective defense against ransomware is building robust cyber-resilience within an organization.
The study also touched on the role of artificial intelligence (AI) in the current threat landscape. In the UK, 65% of surveyed security professionals believe AI has enhanced the effectiveness of attacks that precede ransomware, such as malicious links, business email compromise, malicious attachments, and credential harvesting. While AI is not yet a primary component of ransomware payloads themselves, it is being used to create more convincing phishing lures, improve impersonation attempts, and accelerate system reconnaissance once attackers breach a network.
According to a chief strategy officer at Proofpoint, AI has not fundamentally altered ransomware but has significantly improved the attacks that lead to it. Attackers are leveraging AI to generate highly persuasive phishing emails and credential theft campaigns that exploit human trust on a large scale. The report concludes that organizations that view ransomware solely as an endpoint or recovery issue are overlooking the common starting points of these attacks: people, identities, and trusted communications.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.