Fake 'Ransom Busters' Service Is Actually a Ransomware Insider Running a Side Scam
A criminal pretending to rescue hack victims is really a ransomware affiliate trying to pocket ransom money before his own gang gets it.

Key points
- A group calling itself "Ransom Busters" contacted ransomware victims by email, offering to recover stolen files for fees of $20,000 to $60,000.
- Security firm GuidePoint Research assessed with moderate confidence that Ransom Busters is not a genuine rescue service but a ransomware affiliate running an unauthorised side scheme.
- The same backdoor passwords and attacker-controlled hostnames appeared across multiple victim networks, linking the incidents to a single operator.
- GuidePoint observed the activity across attacks tied to ransomware groups DragonForce, Settra and Anubis.
- Bitcoin payment requests and prices quoted before any scoping call are both strong indicators that outreach like this is fraudulent.
A criminal posing as a cyber-rescue service has been cold-emailing companies that just suffered ransomware attacks, offering to secretly recover their files for a fee. The person sending those emails almost certainly helped steal the files in the first place.
The group calls itself "Ransom Busters." According to a report published today by GuidePoint Security's research team (GRIT), it contacts victims and claims to have broken into the servers of several criminal gangs, discovering the victim's stolen data along the way. For $20,000 to $60,000, it promises to delete that data and hand over the encryption keys, the digital locks criminals use to freeze victims out of their own files. It's a tidy pitch. It's almost certainly a lie.
How did researchers figure out this was a fraud?
GuidePoint's incident-response team worked two separate cases where Ransom Busters made contact, and the two attacks were suspiciously identical. Ransomware incidents usually carry their own fingerprints in tools and techniques, but both cases shared the same internal reconnaissance software, identical backdoor account passwords, and the same attacker-controlled computer hostname. That's not coincidence.
GuidePoint principal threat intelligence consultant Justin Timothy concluded that Ransom Busters is almost certainly a single ransomware affiliate, a contractor who carries out attacks on behalf of larger criminal operations, now trying to collect a separate payment from victims without cutting in the main gang. We've covered DragonForce, one of the groups GRIT ties to this activity, since our report on its attack against One Community FCU on 22 July.
Ransomware-as-a-service, or RaaS, works like a criminal franchise: a core group builds the attack software and manages payment infrastructure while affiliates do the actual hacking for a cut of each ransom. Ransom Busters appears to be one such affiliate, using existing access to run a private shakedown on the side.
Should victims pay Ransom Busters?
No. Even setting aside that payment funds criminals, the offer is likely worthless. In most RaaS operations, the affiliate doesn't control every copy of stolen data. The core gang holds copies too. Timothy told Dark Reading that if both the main gang and Ransom Busters hold the stolen files, any payment for data suppression is "effectively worthless."
| Red flag | What it signals |
|---|---|
| Contact arrives before attack is publicly known | Inside knowledge; not a neutral third party |
| Email sent from ProtonMail or similar private service | No verifiable identity |
| Flat fee quoted before any scoping conversation | Mirrors ransomware extortion tactics |
| Payment requested in Bitcoin | Strong indicator of criminal intent |
| Claims to have hacked the hackers | Potentially illegal under US computer fraud law |
Timothy also noted to Dark Reading that Ransom Busters' tactics undermine the broader RaaS business model, since a side shakedown erodes the credibility that ransomware gangs depend on to collect future payments. That's the detail worth watching: if affiliates routinely defect like this, the trust that holds these criminal franchises together starts to crack.
If your organisation is hit by ransomware and receives unsolicited contact mid-incident, treat it as suspicious by default. Legitimate incident-response firms use verifiable corporate domains, quote nothing until they understand the scope of the problem, and don't ask for cryptocurrency. Any contact that skips those steps deserves the same scepticism as the original attack.



