Researchers say a group calling itself “Ransom Busters” contacted ransomware victims before the attacks became public, pretending to be a recovery firm. The emails offered to delete stolen data and provide decryption keys for $20,000–$60,000, likely diverting payments away from the victim’s original extortionists, with no guarantee data would actually be deleted.
Key findings
- An outfit calling itself “Ransom Busters” emailed ransomware victims before attacks were publicly disclosed, offering a cheaper deal than the original extortion demand.
- The pretext: claiming it “hacked the ransomware gangs themselves” and could delete stolen data and retrieve encryption keys.
- GuidePoint assessed with “moderate confidence” that this is actually a ransomware affiliate trying to redirect payments away from partner gangs (RaaS operations).
- Victims were offered a price range of “between $20,000 and $60,000.”
- GuidePoint warns paying the ‘rescuers’ gives “no assurance that stolen information will actually disappear.”
Who’s being targeted
- Commonly targeted roles: Executive leadership, IT, Security/Incident response, Legal/Privacy, Finance/Accounts Payable.
- Attack channels: email.
- Impersonated: “Ransom Busters” (fake ransomware recovery firm).
Awareness takeaways
- Treat unsolicited “ransomware recovery” outreach as potentially fraudulent, route it through your incident response lead and legal team, not ad-hoc negotiations.
- Do not trust promises that data will be deleted after payment; require independent verification steps and assume data may still be retained or resold.
- If someone knows about your ransomware incident unusually early, treat that as a sign they may be connected to the attackers and escalate immediately.
Red flags to watch for
- Unsolicited contact from an unknown ‘recovery’ firm before the incident is public
- Pressure to pay a new party instead of following your incident response process
- No verifiable proof or enforceable guarantee that stolen data will be deleted
Read the video transcript
Imagine this: your files are locked by ransomware… and before anyone goes public, an email pops up from something called “Ransom Busters.” The message claims, “We have hacked the ransomware gang and located your stolen data; we can delete it and retrieve the encryption keys for a reduced payment between $20,000 and $60,000.” Sounds like a rescue, right? Here’s the twist: researchers say “Ransom Busters” is likely just another ransomware affiliate, trying to hijack the payout. They email victims before the attack is public, push you to pay them instead, and there’s zero proof your stolen data ever disappears. If a mystery “recovery” outfit knows about a ransomware hit and emails you first, treat it as part of the attack, forward it immediately to your incident response lead and legal, and do not engage.