“Ransom Busters” Emails Victims for $60K “Help”

The Hacker News · Medium sophistication
Last updated August 19, 2026

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and pressure victims to pay for “data deletion” and “regaining access,” even though there is no reliable way to verify data removal.

How the scam works

An actor calling itself Ransom Busters has been emailing organizations that recently experienced ransomware incidents. The message claims the sender hacked into the servers used by ransomware groups and can delete the victim's stolen data for a fee ranging from $20,000 to $60,000. The emails request contact with the organization's CEO or IT leadership, and pressure recipients into paying for what is described as help regaining access to files and deleting backups held by the ransomware group.

Why it succeeds

This approach works because it lands during a moment of crisis. Victims are already dealing with the fallout of a ransomware incident and may be desperate for any option that promises to limit damage. Requesting direct contact with the CEO or IT leadership sidesteps normal intake channels and adds urgency, pushing decision makers toward a fast response instead of a verified one. GuidePoint Security notes that legitimate cybersecurity firms typically reach out to ransomware victims only after an attack becomes public knowledge, which makes proactive, pre-disclosure outreach like this suspicious by comparison.

What to watch for

Key red flags in this pattern include:

  • Unsolicited outreach that arrives immediately after an incident, before any public disclosure
  • Requests to bypass normal reporting channels by asking to speak directly with the CEO or IT leadership
  • Promises to delete stolen data or backups in exchange for payment, with no way to verify the claim
  • Framing the offer as a favor or rescue, rather than a standard, disclosed service

As GuidePoint Security puts it, payment to any criminal party offers no guarantee that stolen data will be deleted, and there are no magic bullets for remedying data exfiltration.

Building resistance

Organizations can reduce the risk of falling for this tactic by building it into incident response planning ahead of time:

  • Treat any unsolicited recovery or data-deletion offer received after an incident as a potential extortion attempt, and route it through incident response and legal review rather than direct reply
  • Train executives, IT leadership, and finance staff to recognize requests for direct CEO or IT contact as a manipulation tactic rather than a standard business process
  • Establish clear internal guidance that no third party can be trusted to guarantee deletion of stolen data, regardless of payment
  • Ensure legal and communications teams are looped in early so that extortion attempts are documented and handled consistently

The underlying lesson is that criminal actors, including those posing as helpers, cannot be trusted and may use deceptive tactics to pressure victims into additional payments beyond the original ransomware demand.

Key findings

  • An actor calling itself “Ransom Busters” proactively emails ransomware victims offering to delete stolen data for $20,000–$60,000.
  • The emails request contact with “their CEO or IT leadership,” using a credibility-building story about “found vulnerabilities in administrative panels maintained by RaaS groups.”
  • GuidePoint assesses it is very unlikely to be legitimate and warns it is a deceptive extortion tactic with no guarantee data is deleted.
  • In two incidents analyzed, there were overlaps in tools and artifacts (e.g., SoftPerfect Network Scanner, s5cmd to AWS, an RMM installed via PowerShell, a backdoor account password, and a recurring attacker hostname).

Who’s being targeted

  • Commonly targeted roles: Executive leadership, IT leadership, Security leadership, Finance (for payment/extortion handling), Legal/Compliance, Incident Response team.
  • Affected industries: Multiple industries (victims not specified in article), Financial services (mentioned in related UNC6671 section), Legal services (mentioned in related UNC6671 section).
  • Attack channels: email.
  • Impersonated: “Ransom Busters” (claims to be a helper who can access ransomware servers).

Red flags to watch for

  • Unsolicited outreach immediately after an incident, before anything is public
  • Asks to bypass normal channels by requesting direct contact with the CEO or IT leadership
  • Promises deletion of stolen data/backups for payment (no verifiable guarantee)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Ransom Busters email scam?

It is a scheme where an actor calling itself Ransom Busters emails organizations that recently suffered ransomware incidents, claiming it hacked the ransomware group's servers and can delete the victim's stolen data for a fee between $20,000 and $60,000.

Is Ransom Busters a legitimate recovery service?

No. GuidePoint Security assesses it is very unlikely to be legitimate, and there is no reliable way to verify that any stolen data was actually deleted after payment.

What are the warning signs of this scam?

Red flags include unsolicited outreach right after an incident, requests to contact the CEO or IT leadership directly, and promises to delete stolen data or backups in exchange for payment with no verifiable guarantee.

How should organizations respond if they receive one of these emails?

Treat the email as a potential extortion attempt and route it through the incident response and legal process rather than responding directly or making payment.

Read the video transcript

You’ve just had a ransomware incident… and then this email lands: “We can help you recover and delete your stolen data.” They call themselves “Ransom Busters,” claim they hacked the ransomware group’s servers, and offer to delete your data for $20,000 to $60,000… if your CEO or IT leader talks to them. Here’s the catch: this is a second extortion. There is no reliable way to prove they can delete anything. Unsolicited “recovery help” that wants a direct line to the CEO is a giant red flag. If you ever see a “Ransom Busters” style email, don’t reply, forward it immediately to our incident response and legal contacts, and let them handle it.

Similar attacks

BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Ransomware Crew Poses as “Ransomware Help”

Ransomware Crew Poses as “Ransomware Help”

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and…

August 1, 2026