2026-08-20 · view entry permalink →
"Ransom Busters" emails ransomware victims before their incident is public, offering to delete the stolen data for a fee — and the tooling says it is the same affiliate who took it
An entity styling itself Ransom Busters has been emailing organisations in the middle of a ransomware incident, writing to addresses at the victim's own domain and asking to be put in touch with the chief executive or IT leadership (GuidePoint Security, 2026-08-18). It presents itself as a project that assists victims of cyberattacks, claims to have held unauthorised access to criminal groups' servers for more than three years, says it has found the victim's stolen data on one of those servers, and offers to return the files, destroy the attackers' backups and — because it claims access to the operation's key storage — help restore encrypted data. The fee is $20,000 to $60,000 to delete the stolen data from the ransomware group's servers.
The property that separates this from ordinary ambulance-chasing is when it arrives. GuidePoint notes that legitimate recovery-service solicitation generally follows an attack becoming public knowledge; this outreach lands before the incident is publicly known at all, which means the sender knew about an intrusion nobody had disclosed (GuidePoint Security, 2026-08-18). Responding to two of these incidents, GuidePoint's teams found the same set of artefacts in both victim environments: one network-scanning utility used for internal reconnaissance, one cloud-object-storage command-line tool used to move data out to attacker-controlled cloud storage, one remote-monitoring-and-management tool installed through a PowerShell script as a secondary access channel, a locally created backdoor account whose password was identical in both intrusions, and an identical attacker-controlled workstation name appearing in both. GuidePoint weighed and rejected the obvious innocent explanation — a standardised affiliate playbook or a shared virtual-machine image distributed inside one programme — because the same overlap recurred across incidents belonging to different ransomware operations, which makes it a fingerprint of an operator rather than of a programme. On that basis it assesses with moderate confidence that Ransom Busters is a single affiliate employed across several operations, using affiliate-level access to divert ransom negotiations away from the operation it is working for, and states it observed the behaviour while responding to incidents involving DragonForce, Settra and Anubis (GuidePoint Security, 2026-08-18).
A second incident-response firm has seen the same thing independently. Coveware confirmed to BleepingComputer that it responded to at least one incident involving contact from the same group or individual, and its senior director of incident response drew the same distinction — that what makes this different from a routine recovery-service pitch is the approach to a victim whose incident was not yet public (BleepingComputer, 2026-08-19). No victim is reported to have paid Ransom Busters; in one incident the victim paid the underlying ransomware operator instead.
GRIT assesses with moderate confidence that “Ransom Busters” is not a bona fide third-party victim services firm, but rather a single ransomware affiliate with employment across multiple RaaS operations, using their affiliate access to divert ransom payment discussions away from the original ransomware operation.
We observed this behavior while responding to incidents from threat groups including DragonForce, Settra and Anubis.