A new and particularly dangerous scam is targeting organizations that have already fallen victim to ransomware. Ransom Busters is contacting companies and promising that it can recover files and erase stolen data, asking for up to $60,000.
The activity was first reported by the GuidePoint Research and Intelligence Team (GRIT), which investigated two incidents where victims received unexpected messages from an entity called “Ransom Busters LTD.” The researchers warn that this is not a reliable recovery service.
See also: How businesses negotiate with ransomware groups
What does Ransom Busters promise?
The messages are sent proactively to organizations that have been attacked and request a response from the CEO or IT management. Ransom Busters claims to have identified vulnerabilities in the administrative environments of ransomware-as-a-service (RaaS) and has maintained access to their servers for more than three years.
According to his claims, he found data stolen from the company on a server he hacked. He also claims that he can regain access to encrypted files, remove copies of the data, and interfere with the storage of decryption keys.
For these services, he asks for between $20,000 and $60,000. When recipients asked why payment was required, the operator replied that free help could reveal his access to the criminals' infrastructure. However, none of these claims have been independently verified.

Why researchers consider Ransom Busters suspicious
GRIT links the methodology to incidents involving the DragonForce, Settra, and Anubis. In two separate cases, common tools were identified, a local backdoor account with the password Numlock!123 and the same hostname, DESKTOP-BBETH6K.
The shared technical elements reinforce the assessment that there may be a single operator behind Ransom Busters. GuidePoint believes it is more likely to be an associate of RaaS groups, who uses a different guise to extort additional money from victims.
The tactic moves the negotiation to a second, uncontrolled channel. A victim who has just lost access to critical systems can accept the offer without knowing whether the sender actually has the data or is trying to exploit information from the original attack.
The approach is unusual for another reason: the messages reach companies before the attack is publicly known. Legitimate incident response teams typically contact an organization after it requests help or after the incident has been made public, not with an unsolicited offer that demands immediate payment.
See also: Mikel Coffee ransomware: Attack claim by TheGentlemen

Ransom Busters: What Victims Should Do
GuidePoint calls the independent “rescuer” scenario highly unlikely. Paying any criminal entity does not guarantee that stolen data will be deleted or that access to files will be restored. Organizations should treat the communication as a potential second extortion attempt.
Recipients should not open links or attachments from the messages, nor should they negotiate on their own. The incident response team should be notified immediately, the emails and their headers should be retained for investigation and communication with the relevant authorities. CISA also recommends isolated backups and reporting the incident to the relevant authorities.
GRIT's assessment remains an estimate, not a definitive identification. The common technical findings increase the likelihood of a common actor, but do not by themselves prove who is handling the messages or whether Ransom Busters actually had access to the infrastructure it claims.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
For this reason, every communication must be recorded without modifying the original data. Organizations need to independently check the status of backups, maintain traces of the attack, and follow the recovery plan together with their legal partners.
The SecNews technical team points out that the promise of deleting data from criminals' infrastructures does not constitute evidence of recovery. Until independent evidence is available, this persona should be treated as a potential ransomware partner and not a legitimate recovery partner.
See also: StormEncryptor ransomware changes tactics after Medusa

The incident shows that exploitation does not stop when the initial attack is complete. Criminals can exploit fear, time pressure and uncertainty to pose as “saviors.” Cool verification, documentation and expert assistance remain the safest route.
