This revelation comes from a recent study by Cybereason called Ransomware: The Cost to Business Study 2024. The study also found that of the four in five (78%) of organisations who pay ransom demands and are hit by a second attack, 36% of perpetrators were the same threat actor.
On top of that, nearly two thirds (63%) of these organisations were then asked to pay more the second time. And over half (56%) of the surveyed organisations experienced more than one ransomware incident within the last 24 months, highlighting the persistent and growing menace posed by cyber-criminals.
The study, which involved input from over 1000 cybersecurity professionals, revealed that an alarming 84% of organisations ultimately opted to fulfil ransom demands following a breach. However, the outcomes were far from reassuring, with less than half (47%) successfully recovering their data and services uncorrupted.
“This is problematic on several levels. It’s no guarantee that your data and systems will be returned uncorrupted, that attackers won’t sell your data on the black market, or that you won’t be attacked again,” said Greg Day, global field CISO (VP) at Cybereason.
The decision to pay a ransom was influenced by various factors cited by respondents, including the threat of sensitive information disclosure, fear of business loss, perceived expediency of payment, staffing limitations during holidays or weekends, and, in some cases, concerns for lives at stake or lack of backup files.
The financial ramifications of ransomware attacks are substantial, with nearly half (46%) of victims estimating business losses going up to £7.8 million, and 16% reporting losses exceeding £7.8 million.
Despite the escalating risks and financial toll of ransomware attacks, only 41% of organisations feel adequately equipped to manage future attacks, while uncertainty looms over the extent of cyber insurance coverage.
“This year’s research shows that, while most businesses have a ransomware strategy in place, many are incomplete. They’re either missing a documented plan or the right people to execute it. As a result, we see that many organisations are paying the ransom. Likewise, whilst many have cyber insurance, too many simply don’t know if or to what degree it covers them for ransomware attacks,” said Day.
Recommended reading
- Ransomware Attacks Up 73% in January 2024 Year-on-Year
- NCSC Warns Ransomware Threat to Rise with AI
- New Threat Actors Contribute to Big Rise in Ransomware Attacks
Furthermore, the study underscored a concerning shift towards sophisticated “low-and-slow” ransomware tactics, aimed at infiltrating networks extensively to maximise ransom payments.
Shockingly, over half (56%) of organisations failed to detect breaches for 3-12 months, with ransomware actors exploiting supply chain breaches, direct infiltration, and insider assistance to gain unauthorised access.
The researchers also noted the increasing efficacy of ransomware actors, facilitated by the use of generative AI tools to craft persuasive social engineering messages tailored to diverse linguistic audiences.





