Ransom Busters Demands $20,000–$60,000 From Ransomware Victims

A ransomware affiliate calling itself Ransom Busters has been contacting victim organisations directly, offering to recover data and delete stolen copies from ransomware operators’ servers for payments of $20,000 to $60,000. GuidePoint Research and Intelligence Team (GRIT) said it encountered the activity while responding to incidents involving DragonForce, Settra and Anubis.
The emails seek contact with a chief executive or IT leader. Their sender claims to have identified weaknesses in administrative panels used by ransomware-as-a-service groups, accessed their servers for more than three years, and located the recipient’s stolen data on infrastructure it recently breached.
An unsolicited offer with no assurance
Ransom Busters says a payment would restore access to files and data and remove backups retained by the ransomware group. GRIT said the outreach is anomalous because cyber-security providers may offer recovery assistance after an incident becomes public, rather than proactively approaching an affected organisation in this manner.
GuidePoint considers a legitimate explanation extremely unlikely. Accessing another party’s systems in the way described would violate the U.S. Computer Fraud Abuse Act. Principal Consultant Justin Timothy said the operators were likely concealing the true source of their access or were acting outside the law.
When challenged about charging for the supposed help, the group said unpaid action would endanger its access to the ransomware infrastructure. GRIT’s conclusion is that victims should not interpret the persona as a trustworthy third party: payment to any criminal actor does not guarantee that exfiltrated data will be deleted.
Evidence points to a possible affiliate
GRIT analysed two incidents in which Ransom Busters contacted victims and found notable operational overlap. Both involved SoftPerfect Network Scanner for internal reconnaissance, s5cmd for moving data to cloud storage through AWS, and the Remotely remote monitoring and management tool installed using a PowerShell script.
The investigations also identified a local backdoor account using the password Numlock!123 and the same attacker-controlled hostname, DESKTOP-BBETH6K. Those common elements raise the possibility that one operator, likely an affiliate rather than an outside recovery group, is responsible. The pattern fits the wider risk that familiar enterprise tools and configurations can be abused as an intrusion path, as outlined in attacks affecting SonicWall, SaaS and DNS environments on attacks affecting SonicWall, SaaS and DNS environments.
A fragmented and evolving extortion market
The case comes amid a changing ransomware environment. Check Point recorded 2,139 organisations listed on data-leak sites in the second quarter of 2026, while the number of active groups rose from 71 to 93. The top 10 groups’ share fell from 71% in the preceding quarter to 57.6%, signalling a more fragmented ecosystem.
For businesses, the practical implication is clear: an unsolicited offer to retrieve or erase stolen data should be handled as part of the incident itself, not as a recovery service. Preserve the communications and technical evidence, assess the intrusion through established response processes, and do not rely on a criminal party’s promise to remove copied information.

