- What: Ransomware actor impersonates incident recovery service
- Impact: Victims may be tricked into paying ransoms to fake recovery services
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES INSIDER THREATS DATA PRIVACY THREAT INTELLIGENCE NEWS 'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments. Alexander Culafi,Senior News Writer,Dark Reading August 18, 2026 4 Min Read SOURCE: ANDREYPOPOV VIA GETTY IMAGES A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model. According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as "Ransom Busters" has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters "can return your files to you and destroy all backups held by the group." The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files. LOADING... "We observed this behavior while responding to incidents from threat groups including DragonForce, Settra, and Anubis," according to the blog post, released today. "The threat actor claimed this access allowed them control over 'almost all of their infrastructure. Like [ransomware as a service [RaaS] groups, Ransom Busters' motivation appears to be financial. Ransom Busters confirmed access to the exact same dataset that the ransomware affiliate possessed, when questioned. The group offered to delete the victim's stolen data from the ransomware groups' servers for a fee of between $20,000 to $60,000." Related:Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office Ransom Busters' Red Flags There are multiple red flags behind the purported offer of help, as Justin Timothy, principal threat intelligence consultant at GuidePoint Security, explained in the blog post. For one, in the cases GRIT observed, Ransom Busters reached out before the ransomware attack became public knowledge; incident-response firms usually offer their services after an attack is disclosed. Ransom Busters also claims in its communications to have accessed the administrative panel of ransomware-as-a-service (RaaS) actors. Offensive actions from a third party, Timothy noted, could be considered a violation of the US government's Computer Fraud Abuse Act. LOADING... "We would not expect a legitimate organization to potentially commit a crime, much less to charge a fee in exchange for doing so," Timothy wrote. GuidePoint's Digital Forensics and Incident Response (DFIR) team responded to two incidents where Ransom Busters contacted victims, and in both cases, the intrusions were notably similar (as Timothy wrote, while many intrusions share similar elements, "each attack typically has its own unique characteristics in terms of tooling used and persistence mechanisms within the victim’s network"). There were overlaps in the tools used for internal reconnaissance, data exfiltration, and remote monitoring and management (RMM). The local backdoor accounts also shared a password, and the same attacker-controlled hostname was identified across attacks. Related:Long-running Data Theft Campaign Targeting Salesforce, ServiceNow GRIT ultimately assessed with moderate confidence that Ransom Busters is not a true third-party researcher, but rather a single ransomware affiliate that works with multiple RaaS actors and implements the same tactics across victim environments. The ultimate goal of this, GRIT believes, is that Ransom Busters is "using their affiliate access to divert ransom payment discussions away from the original ransomware operation." In many RaaS operations, affiliates do not have unilateral control over every copy of stolen data or the broader extortion infrastructure. As a result, victims have little ability to verify claims that data has actually been deleted or that all parties with access to the information have relinquished it. GRIT believes the activity may represent an attempt by an affiliate to monetize victims outside the traditional RaaS payment structure, potentially diverting revenue away from the ransomware operation itself. Don't Get Busted by the Busters Timothy tells Dark Reading that Ransom Busters' tactics actually undermine the core RaaS business model. Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition "A standard part of ransom negotiations involves the threat actor's commitment to delete exfiltrated data upon payment. If both the RaaS operation and Ransom Busters retain copies of the stolen data, victims have no reasonable assurance that all copies will be destroyed," he says. "That alone can make any payment for data suppression effectively worthless. From a financial standpoint, Ransom Busters' activity directly damages the credibility and revenue potential of the RaaS operations they are affiliated with." Although he is not aware of a case where these tactics have succeeded, Timothy stresses that a contact made from a non-law enforcement entity mid-incident is very unusual. Legitimate outreach typically comes from a corporate email domain and not a free or privacy-focused service like ProtonMail (Ransom Busters used a privacy-focused email address with no verifiable domain, he adds). "Legitimate IR firms also do not provide pricing before an initial scoping call. They need to understand the incident before quoting anything. Ransom Busters, by contrast, introduced a financial demand early in communications, closely mirroring the behavior of actual ransomware actors," Timothy says. "Finally, no credible cybersecurity vendor requests payment in Bitcoin. That alone should be treated as a strong indicator of malicious intent." About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show. Editor's Choice CYBERSECURITY OPERATIONS From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture byArielle Waldman AUG 6, 2026 4 MIN READ APPLICATION SECURITY Microsoft's Patch Tuesday Deluge Continues With August Updates byJai Vijayan AUG 11, 2026 4 MIN READ CYBERATTACKS & DATA BREACHES Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition byRobert Lemos AUG 12, 2026 4 MIN READ Want more Dark Reading stories in your Google search results? LOADING... Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices