Fake “Ransom Busters” Hijacks Ransom Payments

The Register Security · Medium sophistication
Last updated August 20, 2026

Researchers say a group calling itself “Ransom Busters” contacted ransomware victims before the attacks became public, pretending to be a recovery firm. The emails offered to delete stolen data and provide decryption keys for $20,000–$60,000, likely diverting payments away from the victim’s original extortionists, with no guarantee data would actually be deleted.

Key findings

  • An outfit calling itself “Ransom Busters” emailed ransomware victims before attacks were publicly disclosed, offering a cheaper deal than the original extortion demand.
  • The pretext: claiming it “hacked the ransomware gangs themselves” and could delete stolen data and retrieve encryption keys.
  • GuidePoint assessed with “moderate confidence” that this is actually a ransomware affiliate trying to redirect payments away from partner gangs (RaaS operations).
  • Victims were offered a price range of “between $20,000 and $60,000.”
  • GuidePoint warns paying the ‘rescuers’ gives “no assurance that stolen information will actually disappear.”

Who’s being targeted

  • Commonly targeted roles: Executive leadership, IT, Security/Incident response, Legal/Privacy, Finance/Accounts Payable.
  • Attack channels: email.
  • Impersonated: “Ransom Busters” (fake ransomware recovery firm).

Awareness takeaways

  • Treat unsolicited “ransomware recovery” outreach as potentially fraudulent, route it through your incident response lead and legal team, not ad-hoc negotiations.
  • Do not trust promises that data will be deleted after payment; require independent verification steps and assume data may still be retained or resold.
  • If someone knows about your ransomware incident unusually early, treat that as a sign they may be connected to the attackers and escalate immediately.

Red flags to watch for

  • Unsolicited contact from an unknown ‘recovery’ firm before the incident is public
  • Pressure to pay a new party instead of following your incident response process
  • No verifiable proof or enforceable guarantee that stolen data will be deleted
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your files are locked by ransomware… and before anyone goes public, an email pops up from something called “Ransom Busters.” The message claims, “We have hacked the ransomware gang and located your stolen data; we can delete it and retrieve the encryption keys for a reduced payment between $20,000 and $60,000.” Sounds like a rescue, right? Here’s the twist: researchers say “Ransom Busters” is likely just another ransomware affiliate, trying to hijack the payout. They email victims before the attack is public, push you to pay them instead, and there’s zero proof your stolen data ever disappears. If a mystery “recovery” outfit knows about a ransomware hit and emails you first, treat it as part of the attack, forward it immediately to your incident response lead and legal, and do not engage.

Similar attacks

“Ransom Busters” Emails Victims for $60K “Help”

“Ransom Busters” Emails Victims for $60K “Help”

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and…

August 18, 2026
Ransomware Crew Poses as “Ransomware Help”

Ransomware Crew Poses as “Ransomware Help”

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and…

August 1, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
Fake Transaction Receipt Emails Drop Remote Access Tool

Fake Transaction Receipt Emails Drop Remote Access Tool

Researchers observed real phishing emails posing as transaction receipts to trick people into opening a PDF attachment. The PDF claims an “Adobe Flash Player update is required,” leading victims to download and run a script that silently installs ScreenConnect for persistent remote access.

August 18, 2026
SafePal Leak Fuels Phishing by Fake “Support”

SafePal Leak Fuels Phishing by Fake “Support”

SafePal says an order-tracking plug-in flaw exposed order data for 39,798 customers, including names, contact details, shipping addresses, and purchase information. A customer reported receiving a suspicious email, letter, and phone call from someone pretending to be SafePal and urging them to…

August 17, 2026