Press release goes out, saying the data was "deleted"
Send another ransom, maybe 5 BTC, otherwise data is released
Insert taps on head meme
Imho it’s much better to just sit on it for a few months, then hit the usual forums to market it as high-quality data.
To a criminal that's easily worth an ask of 5BTC - or perhaps x% of annual profits in perpetuity.
An extortion scam is likely to be worth more than the data.
A prolonged extortion scheme can only be done on a low-scale highly-targeted basis, where you can ensure word doesn’t get out.
Most cryptolockers and other random criminals do exactly what they promise because if they don't, their business model will collapse. All of the stolen info isn't worth nearly as much as what universities are willing to pay out if you keep your promises.
It's wicked, but these criminals do have a business incentive to be nice. Their next target will probably pay again if they act smart.
The problem is that smart criminals don't directly attack a single corporation or university, they'll attack a SAAS/IAAS/PAAS provider many of their potential targets use and see what they can get out of the data. In this instance even one university paying out would probably be enough to offset the risk and cost of the criminal operation.
In many cases, paying out is also the economical choice to take, especially in ransomware attacks. Even if backups were made, tested and recent, paying a million here and there might still be worth it if not doing so would cost weeks or even months of work and employees and students lacking IT services. With modern education being run like a business, I'm not sure if it'd even make sense to bet on such a statement to be worth it. You may shoot yourself in the foot when you eventually do get hit and you need to either spend lots of time and money or break the promise you made on your website (betraying your employees and students in the process by showing that you cannot hold up the values you claim to have).
Presumably all competent scammers benefit from being able to repeat the scam, and would lose out if the scam stopped working, so they all have an incentive not to defect.
Scams like this depend on the scammers understanding the incentives better than their targets and so it’s reasonable to assume that the scammers are aware of the context.
However - this is probably true as well: