Earlier quoted context omitted.
The obverse is true - because a ransom organization is dependent upon their reputation, a company claiming to have paid and received confirmation from the group could prevent them from releasing it as well. The general public (including the next victims) don't have a way to confirm if payment was made. ShinyHunters would have to choose between arguing publicly that they were not paid or not releasing the data to prot…
Good/funny observation. Game theory and economics are fun. :D I do think that the partial information problem relating to new entrants into this market is interesting though. The number of potential threat actors with partial/no information but that might speculate based on grandiose visions of ransom or outdated history is high. We see dumb attempts at real-world ransoms/extortion which don't get paid at a pretty hi…
You'll probably get your data leaked anyways, potentially get compromised again (see Instructure situation) and end up in a way worse place if you just shut up and paid it, or let it leak normally.