Incentives matter, and if the ransomeware developers are actually getting paid a lot, they will continue exploiting these vulnerabilities. On the other hand, if it turns out people don't actually bother paying despite being locked out of their computers, would the hackers even bother continuing this line of attack?