Fake “Ransom Busters” Hijacks Ransom Payments

The Register Security · Medium sophistication
Last updated August 20, 2026

Researchers say a group calling itself “Ransom Busters” contacted ransomware victims before the attacks became public, pretending to be a recovery firm. The emails offered to delete stolen data and provide decryption keys for $20,000–$60,000, likely diverting payments away from the victim’s original extortionists, with no guarantee data would actually be deleted.

Key findings

  • An outfit calling itself “Ransom Busters” emailed ransomware victims before attacks were publicly disclosed, offering a cheaper deal than the original extortion demand.
  • The pretext: claiming it “hacked the ransomware gangs themselves” and could delete stolen data and retrieve encryption keys.
  • GuidePoint assessed with “moderate confidence” that this is actually a ransomware affiliate trying to redirect payments away from partner gangs (RaaS operations).
  • Victims were offered a price range of “between $20,000 and $60,000.”
  • GuidePoint warns paying the ‘rescuers’ gives “no assurance that stolen information will actually disappear.”

Who’s being targeted

  • Commonly targeted roles: Executive leadership, IT, Security/Incident response, Legal/Privacy, Finance/Accounts Payable.
  • Attack channels: email.
  • Impersonated: “Ransom Busters” (fake ransomware recovery firm).

Awareness takeaways

  • Treat unsolicited “ransomware recovery” outreach as potentially fraudulent, route it through your incident response lead and legal team, not ad-hoc negotiations.
  • Do not trust promises that data will be deleted after payment; require independent verification steps and assume data may still be retained or resold.
  • If someone knows about your ransomware incident unusually early, treat that as a sign they may be connected to the attackers and escalate immediately.

Red flags to watch for

  • Unsolicited contact from an unknown ‘recovery’ firm before the incident is public
  • Pressure to pay a new party instead of following your incident response process
  • No verifiable proof or enforceable guarantee that stolen data will be deleted
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your files are locked by ransomware… and before anyone goes public, an email pops up from something called “Ransom Busters.” The message claims, “We have hacked the ransomware gang and located your stolen data; we can delete it and retrieve the encryption keys for a reduced payment between $20,000 and $60,000.” Sounds like a rescue, right? Here’s the twist: researchers say “Ransom Busters” is likely just another ransomware affiliate, trying to hijack the payout. They email victims before the attack is public, push you to pay them instead, and there’s zero proof your stolen data ever disappears. If a mystery “recovery” outfit knows about a ransomware hit and emails you first, treat it as part of the attack, forward it immediately to your incident response lead and legal, and do not engage.

Similar attacks

“Ransom Busters” Emails Victims for $60K “Help”

“Ransom Busters” Emails Victims for $60K “Help”

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and…

August 18, 2026
Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026
Revolut Tricked by Fake Govt Requests for Months

Revolut Tricked by Fake Govt Requests for Months

Attackers allegedly stole Revolut customer data by sending fraudulent “government” legal requests for roughly five months. The requests appeared legitimate because they came from a compromised government employee email account, leading Revolut to comply and disclose sensitive personal and financial…

September 17, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Ransomware Crew Poses as “Ransomware Help”

Ransomware Crew Poses as “Ransomware Help”

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and…

August 1, 2026
Fake Gmail Attachment Lure Drops Antino Backdoor

Fake Gmail Attachment Lure Drops Antino Backdoor

A China-nexus threat group targeted government and policy organizations across Asia using spear-phishing emails tailored to the victim’s interests. The emails used spoofed trusted senders and a realistic fake Gmail attachment preview that linked to attacker-controlled pages, ultimately installing…

October 2, 2026