2) Hackers exfiltrate data from the target (this could be source code, database dumps, employee records, emails, or any combination of the above - basically anything that could be seen that has value to the company staying private.
3) Depending on the model used, the hackers either privately or publicly informs entity they have their data and unless a payment of X if made the data will get leaked or sold to the highest bidder.
Or are we really supposed to believe these criminals would follow some sort of made up honor code?
There isn't any measure of morality or honor involved like you are suggesting.
However the hackers also want to get paid, as soon as they go back on their word no one else will ever pay them.
But there is another "maybe" to consider (OP did ask for a brief explanation so I didn't go into all possibilities), did they encrypt the data? If they did and entity no longer has access to it they then have two options 1) restore the data from backup (if they had them and can restore service in a reasonable amount of time) / write off any data loss 2) pay up for the keys.
The hackers are the real victims here
These arm-chair game theory arguments tend to fall apart instantly as soon as you assume multiple rounds are played.