Do companies ever give into straightforward extortion like this? It doesn't seem like it would ever make sense for a company to pay the ransom. Do hackers like these have some kind of smart play that I'm missing?
Companies usually give in to avoid bad press so we’d be unlikely to hear about it. In this case the leak is public knowledge now so CDPR have even less incentive to pay.
It only really obviously makes sense to pay in one scenario: they've encrypted everything (including backups), or you didn't have backups at all. Having immutable / offsite / offline backups may well be less common than one would hope.
Usually they are betting on the company not having any backups in which case they usually do pay the ransom to restore their data.
Nowadays it's usually also a threat to publish company secrets if they don't pay. You can restore your system from backup, but you can't unsteal data with a backup.
If a company has paid for insurance, might make sense to just pay.