/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Investigation finds cyber insurers often prefer to pay the ransom for ransomware attacks, even when backup files could be recovered, to save claim costs

Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom.  Why?

ProPublica Renee Dudley

Context & Ripple Effects

ProPublica's investigation lands on an uncomfortable mechanic already visible in its own coverage: months earlier, two US data recovery firms marketing 'hi-tech' unlocking solutions were found to have simply paid attackers and marked up the bill (data recovery firms quietly paying ransoms). The insurer version is the same arbitrage at larger scale — restoring from backups means funding a slow, uncertain claim, while paying the attacker closes the file cheaply.

The finding matters because it makes insurers a structural buyer in the ransomware market rather than a backstop against it. By mid-2020, ransomware already accounted for 41% of cyber insurance claims, so whichever option carriers systematically choose becomes de facto policy for thousands of victims.

First-order effects

  • Victims — including public agencies — are steered into paying attackers even when their own backups would allow free recovery, because the insurer's cheapest path to closing a claim is the ransom, not the restoration.

Second-order effects

  • Attackers gain a class of counterparties with both the funds and the incentive to pay quickly, which supports higher and more confident ransom demands; the same logic explains why some rings began exfiltrating data before encryption to guarantee payment even from backed-up victims (double-extortion tactics).
  • The practice blurs into the tax code: experts note victims' own ransom payments are likely deductible while insurer-paid ones are not, shifting after-cost calculations depending on who writes the check (ransom payments' tax treatment).

Third-order effects

  • If carriers keep pricing ransom payment below recovery, insurance stops being a hedge against ransomware and becomes its financing layer — inviting underwriting crackdowns, exclusions, and the premium spikes and tightened requirements that hit the industry as attack volumes surged through 2021 (cyber insurance market upheaval).
  • Backup-based resilience loses deterrent value when the payer of last resort prefers capitulation, pushing the real defense burden toward prevention and negotiation specialists rather than recovery.

The trend: Ransomware is evolving from an attack on individual victims into an economy intermediated by insurers and negotiators, whose cost-minimizing choices effectively set the market's payment norms.

Discussion

  • @propublica @propublica on x
    New: Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business.https://www.propublica.org/ ...
  • @propublica @propublica on x
    Ransomware can be good business for insurers even if they pay the ransom. One report found that for every dollar in premiums collected from policyholders, insurers paid out roughly 35 cents in claims. https://www.propublica.org/...
  • @propublica @propublica on x
    One cybersecurity company executive said his firm has been told by the FBI that hackers are specifically extorting American companies that they know have cyber insurance. https://www.propublica.org/...
  • @raj_samani Raj Samani on x
    Coincidence? “#hackers are specifically extorting American companies that they know have cyber insurance. After one small insurer highlighted the names of some of its cyber policyholders on its website, three of them were attacked by #ransomware” https://www.propublica.org/... #m…