The Ransomware Scavengers: 'Ransom Busters' Emails Victims Demanding Up to $60,000
A new outfit is contacting companies already hit by ransomware and offering, for a fee, to wipe their stolen files from the attackers' servers.

Key points
- A group calling itself Ransom Busters is emailing ransomware victims directly and offering to delete their stolen data for between $20,000 and $60,000.
- The offers were flagged by GuidePoint Security researchers who described the unsolicited outreach as clearly anomalous.
- There is no evidence Ransom Busters actually has access to the stolen files or can delete anything.
- Victims paying a second party after a ransomware attack risk funding another criminal operation with no guarantee of results.
A new player has turned up in the messy aftermath of ransomware attacks, and it's not there to help.
Security researchers at GuidePoint have spotted a group calling itself Ransom Busters emailing companies that have recently been hit by ransomware, which is malicious software that locks a company's files and steals copies of them. The pitch is unusual. Ransom Busters claims it has broken into the attackers' own servers and can delete the stolen files, if the victim pays a fee of $20,000 to $60,000. The story was first reported by The Hacker News.
Who is Ransom Busters?
Nobody knows, and that's the point. The group presents itself as a third party swooping in to rescue victims, but researchers see it as another link in the extortion chain, not a break from it.
"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research noted in its writeup. Legitimate incident responders don't cold-email breached companies with a price list.
There's no proof Ransom Busters has actually hacked anyone. Our earlier report from 18 August found a criminal pretending to rescue hack victims is really a ransomware affiliate trying to pocket money before his own gang gets it. An opportunist who reads public leak sites and guesses at victims is another possibility. So is the original gang operating under a new name, hoping to extract a second payment from the same company.
How the scheme works
Ransom Busters targets organisations already in crisis. After a ransomware attack, stolen files usually end up on a leak site run by the criminals, where the victim's name gets published as pressure to pay.
That public listing is a shopping list. Anyone can see who was hit and roughly when. Ransom Busters appears to use those listings to pick targets, then send an email offering a way out: pay us, and the data disappears from the attackers' servers. For a panicked executive staring at a leak-site countdown, a fee well below the original ransom demand can look tempting. That's the whole design.
Should victims pay?
No. There's no way to verify Ransom Busters has any access to the stolen data, no way to confirm anything was deleted, and no recourse if the money vanishes.
| Detail | Figure |
|---|---|
| Fee range demanded | $20,000 to $60,000 |
| Named by | GuidePoint Security |
| Group alias | Ransom Busters |
| Evidence of actual server access | None published |
Paying also creates a second problem. Companies in regulated sectors already have to explain any ransom payment to authorities, and paying an unverified third party looks worse under scrutiny from bodies like the FTC in the United States or the ICO in the United Kingdom.
What affected organisations should do
If a Ransom Busters email lands in an inbox during an active incident, treat it as part of the attack. Forward the message to the incident response team and outside counsel. Preserve the email headers. Don't reply.
Notify law enforcement. The FBI in the US and the National Crime Agency in the UK both track ransomware extortion attempts, including secondary shakedowns like this one. Regulators expect to see that step in the timeline when breach notifications land on their desks.
Assume the stolen data is gone for good. Once files leave a company's network, no payment guarantees their deletion, from the original gang or anyone claiming to have hacked them. The practical upshot: a second invoice doesn't buy silence, it just funds whoever sent it.



