HackMyIP
← Back to News
2026-08-18 The Hacker News

Ransom Busters Scam: Fake Ransomware Hackers Demand Up to $60K From Victims

RansomwareThreat IntelIncident Response

A ransomware affiliate operating under the name Ransom Busters has been identified proactively emailing victim organizations and offering to delete stolen data from ransomware group servers in exchange for fees ranging from $20,000 to $60,000. According to GuidePoint Research and Intelligence Team (GRIT), the third-party outreach is highly unusual, as legitimate cybersecurity firms only contact victims after an attack becomes publicly known. The actor claims to have exploited vulnerabilities in administrative panels maintained by RaaS groups and to have maintained access to their infrastructure for over three years.

GuidePoint's Principal Consultant Justin Timothy noted that the group's justification for charging victims, that operating without compensation would jeopardize their access to threat actor infrastructure, is legally untenable. The activity likely constitutes a violation of the U.S. Computer Fraud and Abuse Act. The modus operandi was observed across incidents attributed to DragonForce, Settra, and Anubis ransomware operations, suggesting the affiliate works across multiple ransomware-as-a-service (RaaS) programs. Organizations should verify the legitimacy of any unsolicited recovery offers and use an email breach checker to determine if their credentials have already been exposed to ransomware affiliates.

Forensic analysis of two incidents revealed striking technical overlaps, indicating a single operator may be behind the activity. Both intrusions used SoftPerfect Network Scanner for internal reconnaissance, s5cmd for data exfiltration to AWS cloud storage, and a remotely deployed RMM tool installed via PowerShell script. Attackers also created a local backdoor account using the password "Numlock!123" and consistently registered under the hostname DESKTOP-BBETH6K, a strong fingerprint for detection engineering and threat hunting teams. Security teams should audit exposed administrative interfaces using a port scanner to identify vulnerable RaaS panel entry points.

The implications for ransomware victims are clear: criminal actors cannot be trusted to negotiate or recover stolen data outside verified law enforcement channels. Paying Ransom Busters offers no guarantee of data deletion and may fund further intrusions against other organizations. Victims should engage professional incident response providers, preserve forensic evidence, and report incidents to relevant authorities rather than responding to unsolicited recovery offers.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →