Earlier quoted context omitted.
They could but also why would they? They can always just hack them again but with a different method this time. The ransom doesn't bind them from hacking the company multiple times. It just obligates them to destroy the data they collected from this attack. As a matter of kindness and good business they'll probably wait a few months or a year or so before poking around again but they'll almost certainly continue poki…
If you squint you can think of it as pen-testing done economically right: how much do you really value your data??
On the one side you have white hat hackers and pen-testers who you pay a contract or salary to prod your system. If you really piss them off (i.e. by stiffing them of their pay) some might just steal your data and threaten to leak it unless you pay them.
On the other side are black hat hackers who will drive by your system and if they find a way to break in they'll offer to keep your data private for a ransom fee. And maybe if you have some charisma, decent pay, and/or a good repertoire you might recruit them on/convert them into white hats for your org.