Fake 'Ransom Busters' Service Is Actually a Ransomware Insider Running a Side Scam
A criminal pretending to rescue hack victims is really a ransomware affiliate trying to pocket ransom money before his own gang gets it.

Key points
- A group calling itself "Ransom Busters" contacted ransomware victims by email, offering to recover stolen files for fees of $20,000 to $60,000.
- Security firm GuidePoint Research assessed with moderate confidence that Ransom Busters is not a genuine rescue service but a ransomware affiliate running an unauthorised side scheme.
- The same tools, backdoor passwords, and attacker-controlled hostnames appeared across multiple victim networks, linking the incidents to a single operator.
- GuidePoint observed the activity across attacks tied to ransomware groups DragonForce, Settra, and Anubis.
- Requesting Bitcoin payment and quoting a price before any scoping call are both strong indicators that outreach like this is fraudulent.
A criminal posing as a cyber-rescue service has been cold-emailing companies that just suffered ransomware attacks, offering to secretly recover their files for a fee. The catch: the person sending those emails almost certainly helped steal the files in the first place.
The group calls itself "Ransom Busters." According to a report published today by GuidePoint Security's research team (GRIT), it contacts victims of ransomware attacks and claims to have broken into the servers of several criminal gangs, discovering the victim's stolen data along the way. For $20,000 to $60,000, it promises to delete that data and hand over the encryption keys, meaning the digital keys that criminals use to lock victims out of their own files.
It sounds like a lucky break. It is not.
How did researchers figure out this was a fraud?
GuidePoint's incident-response team worked two separate cases where Ransom Busters made contact, and the two attacks were suspiciously identical. Ransomware incidents usually carry their own fingerprints in terms of tools and techniques, but both cases shared the same internal reconnaissance software, the same backdoor account passwords, and the same attacker-controlled computer hostname. That is not coincidence.
GuidePoint principal threat intelligence consultant Justin Timothy concluded that Ransom Busters is almost certainly a single ransomware affiliate, meaning a contractor who carries out attacks on behalf of larger criminal operations, and who is now trying to collect a separate payment from victims without cutting in the main gang.
Ransomware-as-a-service, or RaaS, works like a criminal franchise. A core group builds the attack software and manages the payment infrastructure. Affiliates do the actual hacking and get a share of whatever ransom is paid. Ransom Busters appears to be one such affiliate, using the access they already have to victims' systems to run a private shakedown on the side.
Should victims pay Ransom Busters?
No. Even setting aside that payment would fund criminals, the offer is likely worthless. In most RaaS operations, the affiliate does not control every copy of stolen data. The core gang holds copies too. Paying Ransom Busters would not guarantee the data disappears.
Timothy put it plainly: if both the main gang and Ransom Busters hold the stolen files, any payment for data suppression is "effectively worthless."
| Red flag | What it signals |
|---|---|
| Contact arrives before attack is publicly known | Inside knowledge; not a neutral third party |
| Email sent from ProtonMail or similar private service | No verifiable identity |
| Flat fee quoted before any scoping conversation | Mirrors ransomware extortion tactics |
| Payment requested in Bitcoin | Strong indicator of criminal intent |
| Claims to have hacked the hackers | Potentially illegal under US computer fraud law |
The activity was first reported by Dark Reading, whose team spoke directly with Timothy about the mechanics of the scheme.
If your organisation is hit by ransomware and receives unsolicited contact mid-incident, treat it as suspicious by default. Legitimate incident-response firms send email from verifiable corporate domains, quote nothing until they understand the scope of the problem, and never ask for cryptocurrency. Any contact that skips those steps deserves the same scepticism as the original attack.



