Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A group of hackers calling themselves “Ransom Busters” has claimed responsibility for infiltrating servers used by ransomware operators, and is now demanding payment from those same victims in exchange for not revealing their sensitive information. The move has left many experts scratching their heads, wondering how this could happen and what it means for the fight against cybercrime.

At its core, this story revolves around a clever tactic employed by Ransom Busters. By hacking into the servers of ransomware operators, they’ve gained access to vast amounts of sensitive data, including personally identifiable information (PII) and encryption keys used to lock down victims’ systems. With this information in hand, Ransom Busters is now contacting these very same victims, demanding payment – up to $60,000 in some cases – in exchange for not revealing their private details or compromising the integrity of their encrypted data.

But how did they manage to pull off such a daring heist? It appears that Ransom Busters exploited vulnerabilities in the software used by ransomware operators to manage their malicious operations. By infiltrating these servers, they were able to map cross-domain privilege escalation routes and identify key choke points where breaches could be initiated. This allowed them to gain access to sensitive areas of the network, effectively putting them one step ahead of the very people they’re extorting.

This development has significant implications for the cybersecurity landscape. For years, ransomware operators have been able to operate with relative impunity, using their ill-gotten gains to fund further malicious activities. But Ransom Busters’ actions suggest that there may be a new player on the scene, one who’s willing to use unconventional tactics to disrupt the ransomware business model. While some experts are hailing this as a victory for cybersecurity, others are cautioning against celebrating too soon – after all, we’re dealing with extortionists who’ve shown no qualms about exploiting vulnerable systems in the first place.

As this story continues to unfold, one thing is clear: Ransom Busters’ tactics raise important questions about the nature of cybercrime and how we respond to it. Rather than simply focusing on stopping ransomware attacks, perhaps we should be exploring ways to disrupt the underlying business model – or at least, make it more difficult for operators to profit from their nefarious activities.

In practical terms, this development serves as a reminder that cybersecurity is a constantly evolving landscape. To stay ahead of threats like these, individuals and organizations must remain vigilant and proactive in their security measures. This may involve staying up-to-date with the latest patches and updates, implementing robust backup procedures, and exercising caution when interacting with unknown entities online – especially those claiming to offer “help” or “protection” from cyber threats.


Source: The Hacker News — 2026-08-18