Ransom Busters Exposed: Rogue Affiliate Posing as Recovery Firm Steals Payments from Victims
A brazen new tactic has emerged in the world of cybercrime, where a suspected ransomware affiliate is posing as a recovery service to steal payments from victims. Dubbed “Ransom Busters,” this group claims it can provide decryption keys and delete stolen data for a fee, but its true intentions are far more sinister.
GuidePoint Security’s Research and Intelligence Team (GRIT) has been tracking this activity after responding to several recent ransomware attacks where victims received emails from Ransom Busters offering their services. What raises alarm is that these messages were sent before the attacks became public, suggesting an insider with access to sensitive information. GRIT believes Ransom Busters may be a single rogue affiliate using its access to steal ransom payments from the ransomware gangs it works with.
The modus operandi of Ransom Busters is to claim it has exploited vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations, granting it access to encryption keys and data stolen from victims. The group offers to delete the stolen data for a fee, ranging from $20,000 to $60,000. However, GRIT’s analysis reveals that Ransom Busters is likely not a true recovery firm but rather the ransomware affiliate responsible for the attacks.
Evidence points to overlapping activity across multiple RaaS operations, suggesting a single entity using its access to steal from its associates. In one incident, the victim instead paid the RaaS operation behind the attack, while in another case, no payment was made. GRIT warns victims against paying Ransom Busters and advises them to report these incidents to law enforcement.
This new tactic is particularly concerning because it creates a situation where paying the ransomware operation may no longer ensure that everyone with access to the data will honor an agreement not to leak it. This increases the risk for victims, who may end up facing further breaches or reputational damage. Coveware, a ransomware negotiation firm, has also encountered similar “middlemen” using other names as far back as 2024 and warns that this type of interference on non-public incidents is much more concerning.
As cybercrime continues to evolve, it’s essential for victims to be aware of these tactics and not fall prey to false promises. While paying a recovery service may seem like an attractive option, it’s crucial to verify their legitimacy and report any suspicious activity to authorities.
Source: Bleeping Computer — 2026-08-19