1 in 2 ransomware victims who paid got a second demand
AI is making extortion campaigns more effective.
Fresh research shows that 50% of local organisations hit by extortion attacks handed over money to their attackers, yet a large share were later chased for even more.
Proofpoint's 2026 AI-Era Ransomware Report, based on a survey of 953 cybersecurity professionals across 12 countries, found that half of affected Singapore organisations paid despite longstanding guidance from law enforcement against doing so.
Of those, 45% faced a further extortion demand, reflecting a shift in which ransomware has evolved from a single payment event into an ongoing negotiation where attackers hold multiple forms of leverage at once, like continued encryption, stolen data and the threat of public disclosure.
75% of Singapore organisations confirm that data was stolen during ransomware attacks. The report said modern extortion campaigns are less about locking systems and more about acquiring data, identities and persistent access, which can be monetised through repeated demands, sold on criminal marketplaces or used to launch secondary attacks.
Artificial intelligence is making these campaigns more effective. Amongst Singapore organisations that experienced an incident, 68% said AI increased its effectiveness, with 10% saying it significantly increased effectiveness and 58% saying it somewhat did. Only 3% reported no evidence of AI use.
The report found that the most successful campaigns continue to depend on human interaction. Malicious links were identified as the most common initial threat at 53%, followed by malicious attachments and conversation hijacking at 38% each, whilst phishing and email-based social engineering were the initial entry vector in 28% of incidents.
When asked why attacks bypassed existing controls, 45% of Singapore organisations said employees did not suspect the attack because it appeared authentic, whilst 48% attributed the incident to users interacting with malicious content. Proofpoint said that this points to the fact that AI is making social engineering increasingly difficult to distinguish from legitimate business communications.
"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware," said Ryan Kalember, chief strategy officer at Proofpoint. "Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications."