Hackers who receive a ransom payment are statistically likely to return for more, according to new data that reinforces long-standing warnings against negotiating with cybercriminals. Main Developments Cybersecurity firm Proofpoint surveyed 953 companies and found that over one-third of organizations that paid a ransom were subsequently hit with a second extortion demand. The report, published Wednesday, provides concrete evidence that paying hackers does not guarantee an end to the attack. Background Governments have long advised against paying ransom demands, arguing that the practice funds future criminal activity. Security researchers have maintained that extortion racks lack incentives to honor agreements, making good-faith negotiation impossible. Read also: Why finding construction projects is like a treasure hunt Why It Matters The findings undermine the assumption that paying a ransom resolves the incident. Organizations face not only the financial cost of the initial payment but also the risk of repeated demands, amplifying the damage from a single breach. What's Next Companies targeted by ransomware should invest in robust backup systems and incident response plans rather than relying on ransom payments. The Proofpoint data may also influence policymakers to strengthen regulations against paying cybercriminals.