A ransomware affiliate has been caught running a secondary extortion scheme under the name "Ransom Busters LTD" — posing as a legitimate data recovery and incident response firm to extract additional payments from organizations that have already been victimized by ransomware. The scheme was uncovered and publicly detailed by GuidePoint Research and Intelligence Team (GRIT) on August 18–19, 2026.
The operation represents an increasingly sophisticated evolution of double extortion: the same threat actor that breached a victim's environment then contacts that victim through a fabricated professional identity, charging a separate fee for services they have no intention — or ability — to actually deliver.
The Scheme
After a ransomware incident, affected organizations often receive unsolicited outreach from third parties offering recovery assistance. Ransom Busters LTD exploits this dynamic by contacting victims via email, presenting itself as an independent recovery specialist that claims to have:
- Infiltrated the ransomware group's backend servers
- Obtained copies of the victim's stolen data
- Secured access to encryption key storage
For a fee ranging from $20,000 to $60,000, Ransom Busters offers to recover encrypted files and permanently delete all exfiltrated copies from the criminal group's infrastructure.
The pitch is credible enough to fool victims because the actor possesses demonstrably real knowledge of the breach — including details about the stolen dataset that were never made public. Researchers at GRIT confirmed this during incident response engagements: when they analyzed the Ransom Busters contact alongside the responsible ransomware affiliate, both parties held identical copies of the same stolen datasets, proving Ransom Busters is not a third party at all.
The Red Flags
GRIT identified several indicators that should immediately raise suspicion when encountering any unsolicited recovery offer:
- Pre-public contact — Ransom Busters reaches out before the breach has been disclosed publicly. The only way to know who to contact is to be the party that committed the breach.
- Identical stolen data — Ransom Busters possessed the exact same datasets as the responsible ransomware affiliate, confirmed in multiple GRIT engagements.
- Claims of unauthorized access — Legitimate recovery firms do not "infiltrate" criminal servers. Claiming to do so would itself constitute unauthorized computer access under statutes like the CFAA.
- Unenforceable guarantees — No payment can guarantee deletion. Ransomware affiliates in RaaS structures do not have unilateral control over all infrastructure and data copies. The RaaS operator retains copies independently of the affiliate.
Linked Ransomware Operations
GRIT observed Ransom Busters activity during incident responses linked to three ransomware operations:
- DragonForce — operates a "RansomBay cartel" model allowing affiliates to use custom branding on shared infrastructure; claimed 590+ victims as of mid-2026 and accounts for approximately 7% of enterprise incident response caseloads globally
- Settra — a newer RaaS operation
- Anubis — another RaaS group operating through affiliated threat actors
The DragonForce cartel model is particularly notable: affiliates are permitted to operate under their own brand names against DragonForce's shared infrastructure. This may explain how a single affiliate can convincingly present as "Ransom Busters" while simultaneously operating as a DragonForce affiliate — the branding is intentionally separable.
Why Paying Does Not Help
Organizations that pay Ransom Busters face the same fundamental problem as any ransomware payment:
- No enforcement mechanism — There is no contract, escrow, or third-party verification. Payment is made on trust to an actor who has already demonstrated they operate in bad faith.
- Distributed data copies — In RaaS operations, the affiliate, the RaaS operator, and potentially other parties may each hold copies of exfiltrated data. An affiliate cannot compel the operator to delete their copy.
- Continued extortion risk — Paying demonstrates willingness to pay. It does not reduce the likelihood of future contact or data publication.
- Original group still active — Paying Ransom Busters does not resolve the underlying ransomware incident or prevent the original group from publishing or selling the data through their own channels.
What Organizations Should Do
If your organization receives unsolicited contact from "Ransom Busters" or any similar party claiming insider access to ransomware infrastructure:
- Do not engage — Do not respond to the contact, provide additional information, or begin any negotiation.
- Treat it as malicious — The contact itself is a component of the attack, not an offer of assistance.
- Preserve communications — Forward the original email and any subsequent messages to your incident response team and legal counsel unchanged.
- Report to authorities — File a report with the FBI Internet Crime Complaint Center (IC3) at ic3.gov. Include all communications received from the actor.
- Notify your IR team — If you are working with an incident response provider, share the Ransom Busters contact immediately. It provides intelligence about the responsible affiliate.
- Vet any recovery provider — Legitimate incident response and data recovery firms have verifiable business histories, professional references, and do not cold-contact breach victims. Engage providers through known channels such as your cyber insurance carrier or legal counsel.
Broader Implications
The Ransom Busters scheme illustrates how the ransomware ecosystem is continuing to evolve beyond simple encryption-and-ransom models. As organizations have become more resistant to paying ransomware demands — through improved backups and cyber insurance guidance — threat actors are layering additional revenue streams directly into the same incident.
Security teams and C-suite executives should ensure that incident response plans explicitly address unsolicited third-party recovery offers, establishing clear escalation procedures for legal and IR teams when such contact occurs. The instinct to pursue any available recovery option is understandable, but threat actors are now deliberately weaponizing that instinct.
GuidePoint's full GRIT research report is available on their blog at guidepointsecurity.com.