I’ve heard the opposite, that most people do get back their data.
Makes sense to me. The interest of the attacker is to collect the ransom, give them back their data and move on. If word were to get around that you paid money but didn’t get your data back, people would stop paying the ransoms.
Also, I doubt they’d come back for another bite. With hundreds of millions of accounts out there to attack, why focus on one?
The biggest advantage these guys have is that they don’t hit any one victim hard enough to make it worthwhile to spend large sums fighting back. Easier to just pay and move on. To a considerable extent they just fly below the radar.