Ransom Busters Emerges as Rogue Data Remediator
A new actor called Ransom Busters claims to delete stolen data from ransomware servers—for a price. Security researchers warn this is likely a scam exploiting breached organizations.
TL;DR
- Ransom Busters emails victims claiming to delete their stolen data from ransomware servers.
- Fees demanded range from $20,000 to $60,000, raising red flags among security experts.
- The tactic exploits fear and confusion post-breach, potentially compounding victim losses.
- No proof has been provided that Ransom Busters can access or delete any data.
- Organizations are advised to verify all unsolicited post-breach communications.
In a troubling twist to the already chaotic ransomware landscape, a group identifying as "Ransom Busters" has begun contacting organizations that have fallen victim to ransomware attacks. These actors claim they can access and permanently delete sensitive data still held on ransomware operators' servers—but only in exchange for a substantial fee, reportedly between $20,000 and $60,000.
Security researchers from GuidePoint quickly identified the outreach as highly suspicious. The unusual nature of a third party offering post-breach remediation services raises serious concerns about potential follow-on scams or misinformation campaigns designed to further exploit compromised entities.
How Ransom Busters Operates
- Ransom Busters sends unsolicited emails directly to known ransomware victims.
- They claim insider access to ransomware infrastructure to delete exfiltrated data.
- Victims are asked to pay a fee ranging from $20,000 to $60,000 via untraceable methods.
- No independent verification of their capabilities has been confirmed by researchers.
- Their actions could violate computer crime laws even if intentions appear helpful.
Why Security Experts Are Skeptical
- There is no evidence Ransom Busters has legitimate access to ransomware backend systems.
- Such offers bypass normal incident response channels and lack forensic accountability.
- Paying the fee may encourage more financially motivated cybercriminal activity.
- Victims risk losing money without recovering or securing their data.
- Organizations should treat all unexpected post-breach contact as high-risk until verified.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.