All incidents

Ransom Busters extorts victims posing as data recovery service

outageopenAug 18, 2026 — Aug 18, 2026
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

RANSOM Busters has announced that it breached the servers of several ransomware groups and is now contacting victims, claiming it can restore encrypted files for a fee that can reach as high as sixty thousand dollars. The group presents itself as a recovery service while seeking to divert ransom payments away from the original attackers. The Hacker News reported the claim, highlighting the unusual twist in the extortion landscape.

According to GuidePoint Security, Ransom Busters uses unverified email domains and promises decryption keys that it allegedly obtained after infiltrating criminal infrastructure. No common vulnerabilities or CVEs have been linked to the alleged intrusions, suggesting the group may have relied on stolen credentials or exposed remote services. Dark Reading noted that the messages often arrive during an ongoing incident, masquerading as legitimate incident‑response outreach.

The ransom demand is typically requested in cryptocurrency, with the group insisting that payment guarantees the return of data. Victims are told that the fee covers the supposed cost of retrieving decryption tools from the ransomware operators. Researchers warn that there is no verifiable proof that any data is actually restored after payment, and the group’s actions undermine trust in genuine recovery firms.

Security analysts say the scheme reflects a broader trend where cybercriminals pose as helpers to exploit the chaos of a ransomware attack. By inserting themselves between victims and attackers, Ransom Busters creates additional uncertainty about whether paying the original ransom will result in data loss or exposure. The tactic also complicates law‑enforcement efforts to track financial flows associated with ransomware campaigns.

Organisations that receive such solicitations should treat them with extreme scepticism and avoid making any payments until the identity of the caller is verified through established contacts. Incident‑response teams recommend reaching out to trusted providers or internal security officials before engaging any third party that claims to have decrypted files. Any communication from Ransom Busters should be preserved as evidence and reported to relevant authorities.

Defenders are advised to review authentication logs for signs of compromised credentials, enforce multi‑factor authentication on remote access points, and segment networks to limit lateral movement if a breach is suspected. Sharing indicators of compromise with information‑sharing communities can help prevent other firms from falling for the same deception. Staying vigilant and verifying every recovery offer remains the best defence against this evolving extortion method.

Intelligence briefing updated Aug 18, 2026

Ransom Busters
Root sourcewww.guidepointsecurity.com
Timeline Coverage

Swipe to explore timeline