Why paying the ransom doesn't guarantee recovery

Written By: Ontrack

Date Published: Oct 5, 2026, 8:00:00 AM

Why paying the ransom doesn't guarantee recovery

By Shaun Stockman, Senior Director of Business Development, Americas at Ontrack.

I’ve been on many calls, talking to insurers and incident response teams in the middle of live ransomware cases, and the payment question comes up on almost every call.

I want to answer the title question right away, because I think this gets buried too often. Paying the ransom does not guarantee you get your data back. Sophos's 2025 State of Ransomware report found that just under half, 49%, of organizations that paid the ransom recovered their data. We have been involved in cases where the decryption key worked fine. I've also sat in on calls where it corrupted half the files it touched. If you're an insurer weighing a payment decision, or a DFIR team on the phone with a client at 2am, I think this is worth thinking about before anyone wires money to an attacker.

Key takeaways

    • Paying a ransom does not guarantee full data recovery. Multiple 2025 studies put the odds of full recovery after payment well under 100%, and some put it close to a coin flip.
    • Decryption tools built by attackers are often unreliable. They can corrupt files, choke on large files, or simply not exist for every version of a given ransomware strain.
    • Double extortion means paying to unlock your files doesn't stop your stolen data from surfacing elsewhere. Roughly 18% of victims who paid still had their data exposed on the dark web.
    • Running a parallel data recovery assessment, before or alongside any ransom negotiation, gives you a second path that doesn't depend on trusting the people who attacked you.

What actually happens when you pay

Most ransom payments today go through a negotiator, and the number that changes hands is rarely the number on the ransom note. Sophos found that companies who paid in 2025 handed over 85% of the initial demand on average, and more than half negotiated the number down. Once payment clears, the attacker is supposed to send a decryption tool. I say "supposed to" because that's where things get uneven.

These tools are usually built fast, under pressure, by the same group that wrote the ransomware. They're not tested the way commercial software is tested. Coveware, which handles ransomware recovery cases for a living, has documented decryptors that damage files instead of restoring them, and ransomware variants where files over a certain size simply fail to come back, no matter what key you have. The attacker has no incentive to fix that bug for you after they've already been paid.

There's another problem that doesn't get talked about enough. Even when the decryptor works, it's usually a crude command-line tool with no documentation and no support line. Someone on your IT team, already exhausted from a week of incident response, has to figure out how to run it across hundreds or thousands of machines without making things worse. I've seen recovery timelines stretch by days just from that step alone, separate from whether the decryption itself succeeds.

If you're in the early hours of an attack right now, our ransomware attack guide walks through what to do before you get anywhere near a payment decision, and it's a better use of the first hour than negotiating.

The recovery numbers tell a mixed story

Here's where I want to be careful, because the statistics floating around aren't all measuring the same thing. Sophos reports that 97% of organizations that had data encrypted got some of it back, through a combination of backups, decryption, and payment. That sounds reassuring until you look closer. Backup-based recovery is at its lowest point in six years, which pushes more organizations toward the ransom option by default rather than by choice. And of the ones who chose to pay, again, only about half got their data back as a direct result of that payment.

Other researchers land in a similar range. Some reports put full recovery after payment closer to 60%. Others, looking at Q4 2024 data specifically, found the failure rate on full recovery even higher. I'm not totally sure which number applies to any one company's specific case, since it depends heavily on the ransomware variant and how fast the response team moved. But every version of this data points the same direction: paying is a bet, not a transaction.

Why decryption keys don't always work

The technical reasons are worth knowing, because they explain why this isn't just bad luck. Encryption implementations written under deadline pressure carry bugs, and once a file is encrypted incorrectly, no key fixes that. Some ransomware generates keys per machine rather than per file, so a network with mixed infection points needs multiple keys the attacker may not have tracked. Partial encryption, where the process was interrupted by an EDR tool or a shutdown, leaves files in a state no decryptor was built to handle.

We wrote more about this trade-off in our piece on whether to pay the ransom, and the short version is that a rapid assessment from a recovery specialist, run before the payment decision, tells you a lot more about what's actually recoverable than the ransom note does.

Double extortion changes the math

Paying doesn't erase the copies of your data the attacker already took. Double extortion, where files are encrypted and stolen at the same time, is now closer to the norm than the exception. You can pay, get a working decryptor, and still end up dealing with your customer data on a leak site three months later, because the payment only ever covered the decryption key, not a promise to delete anything.

There's a legal and regulatory layer here too, one that I think gets underweighted in the moment. If regulated data was stolen, most breach notification laws don't care whether you paid a ransom to get it back. The disclosure obligation exists because the data left your control, full stop. I've talked to legal teams who assumed a successful ransom negotiation closed the book on their exposure, only to find out weeks later that it didn't touch the notification requirement at all.

This is also where the recovery side of the business, separate from the ransom side, tends to get overlooked. Ontrack has recovered data from ransomware attacks without any ransom being paid at all, including cases where backups themselves been wiped by the attacker. Our ransomware recovery case examples cover a few of those, and they're a good reminder that "pay or lose everything" is a false choice more often than people assume.

What to actually do with this

If you're an insurer, build the recovery assessment into your claims workflow as a parallel track, not a fallback after negotiation fails. If you're a DFIR team, preserve the encrypted data and any backup tapes exactly as they are before anyone talks about a factory reset. A drive that's been reformatted or a tape that's been overwritten closes doors that a specialist could otherwise open.

Treat the ransom payment as one option on the table, not the default move. In my experience, the cases that end well are the ones where recovery and negotiation happen at the same time, run by different people, so the payment decision gets made with real information instead of under pressure with none.

FAQ

Does paying the ransom guarantee I'll get all my files back?

No. Recent data puts the odds of full recovery after payment somewhere between 49% and 60%, depending on the study and the ransomware variant involved.

Can a decryption tool actually damage my data?

Yes. Attacker-built decryptors are rarely tested the way commercial recovery software is, and there are documented cases of them corrupting files instead of restoring them, particularly with larger files.

I already paid and the decryption failed. What now?

Stop running the decryptor and don't attempt further do-it-yourself fixes on the affected drives. Preserve the current state and bring in a data recovery specialist who can assess what's still intact underneath the failed decryption attempt.

Should insurers just build the ransom payment into every claim?

That's a coverage and risk decision I'd leave to the insurer's own underwriting and legal teams, but I think the data supports treating payment as a last resort rather than a first move, given how often it fails to deliver full recovery on its own.

Closing thought

The ransom decision isn't going away, and the numbers behind it aren't improving on their own. I think the smartest move, for insurers and incident responders alike, is to stop treating recovery and negotiation as sequential steps and start running them side by side.

 

Subscribe

KLDiscovery Ontrack, LLC, 9023 Columbine Road Eden Prairie, MN 55347, United States (see all locations)