The sequence of the learning platform incident illustrates the dilemma any attacked organisation faces: the company chose to patch the flaw rather than negotiate, and the group responsible answered with an outage displaying a ransom note to every user.
Retaliation is the part that rarely appears in the recommendations. Experts agree that paying funds the next operation and doesn't guarantee the data is deleted, but the recommendation is usually given without describing what happens to those who follow it.
What happens is exactly this: having lost leverage over the data, the attacker looks for another, and the cheapest one is public embarrassment at a peak moment.
That's why the decision not to negotiate has to be taken before the incident, when nobody is under pressure, and it has to come with preparation for the second round: communications ready, the ability to operate with degraded systems, and backups that have been tested.
A company deciding in the moment usually decides badly, because the only bill on the table then is the short-term one.
