A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and pressure victims to pay for “data deletion” and “regaining access,” even though there is no reliable way to verify data removal.
How the scam works
An actor calling itself Ransom Busters has been emailing organizations that recently experienced ransomware incidents. The message claims the sender hacked into the servers used by ransomware groups and can delete the victim's stolen data for a fee ranging from $20,000 to $60,000. The emails request contact with the organization's CEO or IT leadership, and pressure recipients into paying for what is described as help regaining access to files and deleting backups held by the ransomware group.
Why it succeeds
This approach works because it lands during a moment of crisis. Victims are already dealing with the fallout of a ransomware incident and may be desperate for any option that promises to limit damage. Requesting direct contact with the CEO or IT leadership sidesteps normal intake channels and adds urgency, pushing decision makers toward a fast response instead of a verified one. GuidePoint Security notes that legitimate cybersecurity firms typically reach out to ransomware victims only after an attack becomes public knowledge, which makes proactive, pre-disclosure outreach like this suspicious by comparison.
What to watch for
Key red flags in this pattern include:
- Unsolicited outreach that arrives immediately after an incident, before any public disclosure
- Requests to bypass normal reporting channels by asking to speak directly with the CEO or IT leadership
- Promises to delete stolen data or backups in exchange for payment, with no way to verify the claim
- Framing the offer as a favor or rescue, rather than a standard, disclosed service
As GuidePoint Security puts it, payment to any criminal party offers no guarantee that stolen data will be deleted, and there are no magic bullets for remedying data exfiltration.
Building resistance
Organizations can reduce the risk of falling for this tactic by building it into incident response planning ahead of time:
- Treat any unsolicited recovery or data-deletion offer received after an incident as a potential extortion attempt, and route it through incident response and legal review rather than direct reply
- Train executives, IT leadership, and finance staff to recognize requests for direct CEO or IT contact as a manipulation tactic rather than a standard business process
- Establish clear internal guidance that no third party can be trusted to guarantee deletion of stolen data, regardless of payment
- Ensure legal and communications teams are looped in early so that extortion attempts are documented and handled consistently
The underlying lesson is that criminal actors, including those posing as helpers, cannot be trusted and may use deceptive tactics to pressure victims into additional payments beyond the original ransomware demand.
Key findings
- An actor calling itself “Ransom Busters” proactively emails ransomware victims offering to delete stolen data for $20,000–$60,000.
- The emails request contact with “their CEO or IT leadership,” using a credibility-building story about “found vulnerabilities in administrative panels maintained by RaaS groups.”
- GuidePoint assesses it is very unlikely to be legitimate and warns it is a deceptive extortion tactic with no guarantee data is deleted.
- In two incidents analyzed, there were overlaps in tools and artifacts (e.g., SoftPerfect Network Scanner, s5cmd to AWS, an RMM installed via PowerShell, a backdoor account password, and a recurring attacker hostname).
Who’s being targeted
- Commonly targeted roles: Executive leadership, IT leadership, Security leadership, Finance (for payment/extortion handling), Legal/Compliance, Incident Response team.
- Affected industries: Multiple industries (victims not specified in article), Financial services (mentioned in related UNC6671 section), Legal services (mentioned in related UNC6671 section).
- Attack channels: email.
- Impersonated: “Ransom Busters” (claims to be a helper who can access ransomware servers).
Red flags to watch for
- Unsolicited outreach immediately after an incident, before anything is public
- Asks to bypass normal channels by requesting direct contact with the CEO or IT leadership
- Promises deletion of stolen data/backups for payment (no verifiable guarantee)
Frequently asked questions
What is the Ransom Busters email scam?
It is a scheme where an actor calling itself Ransom Busters emails organizations that recently suffered ransomware incidents, claiming it hacked the ransomware group's servers and can delete the victim's stolen data for a fee between $20,000 and $60,000.
Is Ransom Busters a legitimate recovery service?
No. GuidePoint Security assesses it is very unlikely to be legitimate, and there is no reliable way to verify that any stolen data was actually deleted after payment.
What are the warning signs of this scam?
Red flags include unsolicited outreach right after an incident, requests to contact the CEO or IT leadership directly, and promises to delete stolen data or backups in exchange for payment with no verifiable guarantee.
How should organizations respond if they receive one of these emails?
Treat the email as a potential extortion attempt and route it through the incident response and legal process rather than responding directly or making payment.
Read the video transcript
You’ve just had a ransomware incident… and then this email lands: “We can help you recover and delete your stolen data.” They call themselves “Ransom Busters,” claim they hacked the ransomware group’s servers, and offer to delete your data for $20,000 to $60,000… if your CEO or IT leader talks to them. Here’s the catch: this is a second extortion. There is no reliable way to prove they can delete anything. Unsolicited “recovery help” that wants a direct line to the CEO is a giant red flag. If you ever see a “Ransom Busters” style email, don’t reply, forward it immediately to our incident response and legal contacts, and let them handle it.