The Ransomware Scavengers: 'Ransom Busters' Emails Victims Demanding Up to $60,000
A new outfit is contacting companies already hit by ransomware and offering, for a fee, to wipe their stolen files from the attackers' servers.

Key points
- A group calling itself Ransom Busters is emailing ransomware victims directly and offering to delete their stolen data for between $20,000 and $60,000.
- The offers were flagged by GuidePoint Security researchers who described the unsolicited outreach as clearly anomalous.
- There is no evidence Ransom Busters actually has access to the stolen files or can delete anything.
- Victims paying a second party after a ransomware attack risk funding another criminal operation with no guarantee of results.
A new player has turned up in the messy aftermath of ransomware attacks, and it is not there to help.
Security researchers at GuidePoint have spotted a group calling itself Ransom Busters emailing companies that have recently been hit by ransomware, which is malicious software that locks a company's files and steals copies of them until a payment is made. The pitch is unusual. Ransom Busters claims it has broken into the attackers' own servers and can delete the stolen files, if the victim pays a fee of $20,000 to $60,000.
The story was first reported by The Hacker News.
Who is Ransom Busters?
Nobody knows, and that is the point. The group presents itself as a third party swooping in to rescue victims, but researchers see it as another link in the extortion chain, not a break from it.
"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research noted in its writeup. Legitimate incident responders do not cold-email breached companies with a price list.
There is no proof Ransom Busters has actually hacked anyone. It could be an affiliate of a ransomware gang running a side hustle. It could be an opportunist who reads leak sites and guesses at victims. It could be the original attackers under a new name, hoping to squeeze a second payment out of the same company.
How the scheme works
Ransom Busters targets organisations that are already in crisis. After a ransomware attack, stolen files usually end up on a leak site run by the criminals, where the victim's name gets published as pressure to pay.
That public listing is a shopping list. Anyone can see who was hit, and roughly when. Ransom Busters appears to use those listings to pick targets, then send an email offering a way out: pay us, and we will make sure the data disappears from the attackers' servers.
The fee sits well below a typical ransom demand, which can run into millions. For a panicked executive staring at a leak-site countdown, $40,000 to make a problem go away can look tempting. That is the whole design.
Should victims pay?
No, and the reasoning is straightforward. There is no way to verify Ransom Busters has any access to the stolen data, no way to confirm anything was deleted, and no recourse if the money vanishes.
| Detail | Figure |
|---|---|
| Fee range demanded | $20,000 to $60,000 |
| Named by | GuidePoint Security |
| Group alias | Ransom Busters |
| Evidence of actual server access | None published |
Paying also creates a second problem. Companies in regulated sectors already have to explain any ransom payment to authorities, and paying an unverified third party looks worse, not better, under scrutiny from bodies like the FTC in the United States or the ICO in the United Kingdom.
What affected organisations should do
If a Ransom Busters email lands in an inbox during an active incident, treat it as part of the attack, not a solution to it. Forward the message to the incident response team and outside counsel. Preserve the email headers. Do not reply.
Notify law enforcement. The FBI in the US and the National Crime Agency in the UK both track ransomware extortion attempts, including secondary shakedowns like this one. Regulators expect to see that step in the timeline when breach notifications land on their desks.
And assume the stolen data is gone for good. Once files leave a company network, no payment guarantees their deletion, from the original gang or anyone claiming to have hacked them.



