They refuse to pay a ransom... and fund cybersecurity
Cybersecurity: your company is paralyzed by a cyberattack. Stolen data, locked systems, a ransom demanded. Panic, stress, media pressure. A

Imagine: your company is paralyzed by a cyberattack.
Stolen data, locked systems, a ransom demanded.
Panic, stress, media pressure.
And then, instead of negotiating in the shadows...
You do the opposite of everyone else.
You refuse to pay,
you publicly apologize,
and you hand the money demanded over to cybersecurity researchers.
Madness? A PR stunt? Or just plain logic?
Yet that is exactly what happened at the end of 2025.
And it may be the most courageous act we have seen in the digital world in a long time.
We saw it go by like a rare anecdote, almost unreal, in the flow of cyber news:
A company hit by ransomware refused to pay, publicly apologized to its customers...
...and gave the equivalent of the ransom to a cybersecurity research organization.
A drop of ethics in an ocean of denial.
But what we are a little too quick to call a "miracle" says a great deal about the state of our cyber culture today: we marvel at behavior that, in theory, should be... the norm.

What actually happened at Checkout.com?
That company has a name: Checkout.com, one of the major European online payment platforms. On 14 November 2025, it disclosed that it had been targeted by the ShinyHunters extortion group, which got hold of a legacy third-party cloud storage system, left abandoned since 2020. Internal operational documents, merchant onboarding material, a few copies of identity documents dating from 2010 to 2019: nothing touching the live payment platform, no card numbers, no merchant funds. Less than 25% of its current merchant base is affected.
Then comes the response. In a statement signed by its chief technology officer Mariano Albera, the company writes in black and white: "We will not be extorted by criminals. We will not pay this ransom." And it adds a gesture nobody saw coming: donating the equivalent of the sum demanded to cybersecurity research, for the benefit of Carnegie Mellon University and the University of Oxford Cyber Security Center. The specialist press has put the amount at more than a million dollars.
Refusing to pay, saying everything out loud, and turning extortion into funding for collective defence: that is a triple counter-move. Rather than giving in, Checkout.com told the truth, owned up to its responsibilities, and decided that the money would not fund crime, but the solution. It did not "buy back" its image. It made a choice of principle.
What 90% of companies do, in silence
In the vast majority of cases, companies hit by ransomware keep a low profile.
They try to limit the damage:
- downplay their communication;
- negotiate with the attackers;
- sometimes even pay the ransom on the quiet.
Why? To "protect their reputation," "buy time," or because insurers push them in that direction.
But this short-term management reflex only feeds the business model of cybercriminals.
Every ransom settled is encouragement for the next one.
And that reflex is still massive. According to the 2025 edition of the Sophos State of Ransomware report, nearly half of the organizations hit paid to get their data back, one of the highest rates in six years. The median payment still stands at one million dollars, down by half from the two million of 2024, a sign that negotiation and refusal are starting to weigh.
Why paying a ransom makes the problem worse
You often hear: "Better to pay, get the data back, and move on."
Except that paying settles almost nothing, and sometimes makes everything worse:
- Nothing guarantees you get everything back. Sophos notes that in 2025 only 54% of companies were able to restore their data from backups, the lowest level in six years. The rest depends on a key supplied by the attacker, which does not always decrypt every file.
- With data-theft extortion, you are no longer paying for decryption but for a promise of deletion that you will never be able to verify. Stolen data can stay stored, leak again or be resold.
- And in every case, the payment funds the next attack. Every ransom settled makes the adversary that bit more professional.
So it is not a "lesser evil."
It is a headlong rush.
Does paying really guarantee you get your data back?
No, and the 2025 landscape confirms it. Where ransomware used to encrypt everything in order to sell a key, extortion has shifted towards the outright theft of data. Coveware, an incident response specialist, notes that in the second quarter of 2025 only 26% of victims agreed to pay, an all-time low. But the amounts are exploding in the rare cases where stolen data serves as leverage: a median payment of 400,000 dollars, an average above one million.
In other words: fewer and fewer companies pay, and those that give in do so for heavier and heavier sums, with no guarantee other than the word of a blackmailer. That is why the French public scheme Cybermalveillance.gouv.fr is unambiguous: it recommends not paying, filing a complaint and preserving the evidence. Checkout.com did not invent some fringe stance, it simply followed the official guidance, in public.
Cybersecurity: a matter of servers or of culture?
What Checkout.com has just done is change the narrative:
- It does not cast itself as a victim.
- It does not hide behind technology.
- It does not settle for "managing."
It sends a clear message:
"Cybersecurity is a collective issue.
We did not measure up, so we are taking part in the solution."
And this simple gesture could have more impact than all the awareness reports in the world.
Because this case proves one essential thing:
cybersecurity is not a matter of servers, it is a matter of culture.
Of posture. Of values.
You do not need to be an expert to make the right choices.
But you have to dare to make them.
We need leaders capable of saying:
"We were not perfect. But we are not going to make things worse."
What if this were real digital leadership?
Because the real question is not "how to protect yourself 100%."
(Hint: it is impossible.)
The real question is:
- How you respond when it happens.
- What example you set.
- What contribution you make to the ecosystem.
Today, every digital organization lives in a high-risk environment.
But risk does not justify passivity.

In my book Être en cybersécurité, I never promised any "miracle solution."
But I have always argued a simple idea:
You do not build security on fear, but on clear-sightedness.
And sometimes, the only real bulwark is the courage to say no.
It is not for ransomware to write the rules of the game.
And it is not for companies to feed its parallel economy.
A weak signal worth amplifying
Will this case become the norm? Probably not.
But it is a weak signal worth amplifying.
An example we can hold up against every complicit silence.
A gesture that shows digital dignity still exists.
And if it needs saying loud and clear:
No, you must not pay ransoms.
But yes, you can do better than survive an attack.
You can draw a lesson from it that helps everyone.
Sources
- Checkout.com statement signed by its chief technology officer Mariano Albera, "Protecting our Merchants: Standing up to Extortion", 14 November 2025.
- ShinyHunters attack, legacy system and donation to research: BleepingComputer, 14 November 2025.
- Payment rate, median ransom and use of backups: Sophos, "The State of Ransomware 2025", June 2025.
- Share of victims paying and amounts in the second quarter of 2025: Coveware by Veeam, July 2025.
- Official recommendation not to pay and reflexes in a ransomware incident: Cybermalveillance.gouv.fr (in French).
Frequently asked questions
What did Checkout.com do when ShinyHunters demanded a ransom?
Instead of negotiating in the shadows, the company refused to pay, publicly apologized to its customers and donated the equivalent of the ransom to cybersecurity research, for the benefit of Carnegie Mellon University and the University of Oxford Cyber Security Center.
Should you pay a ransom in a ransomware attack?
No. The French public scheme Cybermalveillance.gouv.fr recommends not paying, filing a complaint and preserving the evidence. Paying does not guarantee you get your data back and, in every case, it funds a new attack.
Does paying guarantee you get your data back?
No. In 2025, according to Sophos, only 54% of companies restored their data from backups, the lowest level in six years. With data-theft extortion, you are no longer paying for decryption but for an unverifiable promise of deletion: stolen data can stay stored, leak again or be resold.
How many companies still pay the ransom?
Nearly half of the organizations hit paid in 2025 according to the Sophos State of Ransomware report, with a median payment of one million dollars, down by half from 2024. Coveware, for its part, records an all-time low of 26% of victims paying in the second quarter of 2025.
Is cybersecurity a purely technical problem?
No. This case shows that cybersecurity is above all a matter of culture, posture and values. You do not need to be an expert to make the right choices, but you have to dare to make them.
How is this gesture a matter of digital leadership?
Because the real question is not how to protect yourself 100%, which is impossible, but how to respond when the attack comes, what example you set and what contribution you make to the ecosystem.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
