Study: 80% of organizations that paid a ransom were hit by a second ransomware attack; 66% orgs cited revenue losses after the attack and 53% cited brand damage
Context & Ripple Effects
Paying the ransom has been sold as the fast way out, but the data keeps undercutting that pitch. A CrowdStrike survey of 2,200 organizations found 27% of ransomware victims paid, at an average of roughly $1.1M — and this new study shows most of those payments bought no safety: 80% of payers were hit a second time, with 66% reporting revenue losses and 53% reporting brand damage.
The timing matters because attacker pressure was already escalating: a [[a:1159325|Q2 2021 analysis counted 740 organizations with data posted to leak sites, up 47% quarter over quarter]]. Double extortion means victims now face the payment decision with their data already exposed — and the study suggests the payment itself marks them as proven payers.
First-order effects
- Organizations that pay are not recovering — 80% get hit again, and the majority also absorb revenue losses (66%) and brand damage (53%), meaning the ransom is an added cost on top of the breach, not a substitute for remediation.
Second-order effects
- Cyber insurers face a worsening book: ransomware already accounted for 41% of cyber insurance claims in H1 2020 with average demands up 47%, and a payer base that gets re-attacked pushes claim frequency and pricing pressure higher.
Third-order effects
- If paying reliably invites a second attack, the market logic of ransom payment as recovery collapses — pushing organizations toward prevention and resilience spending and giving regulators and insurers grounds to treat payment as a control failure rather than a business decision.
The trend: Ransomware is evolving from a single-payment shakedown into a repeat-extortion model where payment history itself identifies the most profitable victims.