Fake “Ransom Busters” Hijacks Ransom Payments

The Register Security · Medium sophistication
Last updated August 20, 2026

Researchers say a group calling itself “Ransom Busters” contacted ransomware victims before the attacks became public, pretending to be a recovery firm. The emails offered to delete stolen data and provide decryption keys for $20,000–$60,000, likely diverting payments away from the victim’s original extortionists, with no guarantee data would actually be deleted.

Key findings

  • An outfit calling itself “Ransom Busters” emailed ransomware victims before attacks were publicly disclosed, offering a cheaper deal than the original extortion demand.
  • The pretext: claiming it “hacked the ransomware gangs themselves” and could delete stolen data and retrieve encryption keys.
  • GuidePoint assessed with “moderate confidence” that this is actually a ransomware affiliate trying to redirect payments away from partner gangs (RaaS operations).
  • Victims were offered a price range of “between $20,000 and $60,000.”
  • GuidePoint warns paying the ‘rescuers’ gives “no assurance that stolen information will actually disappear.”

Who’s being targeted

  • Commonly targeted roles: Executive leadership, IT, Security/Incident response, Legal/Privacy, Finance/Accounts Payable.
  • Attack channels: email.
  • Impersonated: “Ransom Busters” (fake ransomware recovery firm).

Awareness takeaways

  • Treat unsolicited “ransomware recovery” outreach as potentially fraudulent, route it through your incident response lead and legal team, not ad-hoc negotiations.
  • Do not trust promises that data will be deleted after payment; require independent verification steps and assume data may still be retained or resold.
  • If someone knows about your ransomware incident unusually early, treat that as a sign they may be connected to the attackers and escalate immediately.

Red flags to watch for

  • Unsolicited contact from an unknown ‘recovery’ firm before the incident is public
  • Pressure to pay a new party instead of following your incident response process
  • No verifiable proof or enforceable guarantee that stolen data will be deleted
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your files are locked by ransomware… and before anyone goes public, an email pops up from something called “Ransom Busters.” The message claims, “We have hacked the ransomware gang and located your stolen data; we can delete it and retrieve the encryption keys for a reduced payment between $20,000 and $60,000.” Sounds like a rescue, right? Here’s the twist: researchers say “Ransom Busters” is likely just another ransomware affiliate, trying to hijack the payout. They email victims before the attack is public, push you to pay them instead, and there’s zero proof your stolen data ever disappears. If a mystery “recovery” outfit knows about a ransomware hit and emails you first, treat it as part of the attack, forward it immediately to your incident response lead and legal, and do not engage.

Similar attacks

“Ransom Busters” Emails Victims for $60K “Help”

“Ransom Busters” Emails Victims for $60K “Help”

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and…

August 18, 2026
Ransomware Crew Poses as “Ransomware Help”

Ransomware Crew Poses as “Ransomware Help”

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and…

August 1, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

Researchers tied to the Aurora ransomware group described a real intrusion that started with aggressive email bombing, then phone calls where attackers posed as the IT help desk to “help” employees fix the issue. Separate reporting shows the same group used the Cursor AI coding assistant to plan…

August 31, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026