Adverse Cyber Extortion Outcomes Happen More Often Than Victims Are Told
Veeam, Thursday, July 30th, 2026
Veeam's Q2 data challenges the advice that paying ransomware operators reliably resolves an incident.
When law enforcement agencies took down the LockBit ransomware group in February 2024, the discovery that LockBit had retained victims' stolen data despite promising deletion exposed a flaw in advice commonly given to victims.
Veeam's Q2 2026 cyber extortion data shows adverse outcomes after payment occur more often than victims are told at the time of the decision. The post covers what the data shows about payment outcomes and where the advisory gap comes from.
It argues recovery capability, not payment, is the reliable path. The analysis is aimed at organizations setting ransomware response policy in advance.