you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / security
24 August 2026 security 5 min read

Ransom Busters and the fake recovery firm: when the attacker offers to help

A company hit by ransomware received an unexpected email while its incident response was still underway. The sender called itself 'Ransom Busters' and claimed it had hacked into the criminal servers holding the victim's stolen data. For a fee, it offered to supply decryption keys, restore files, and delete everything the attackers had exfiltrated. The pitch arrived before the attack was publicly known anywhere. That timing detail is what unraveled the whole story: researchers concluded the helpful stranger was almost certainly one of the people who carried out the attack.

How the Double-Dip Scam Works

GuidePoint Security's Research and Intelligence Team (GRIT) documented the scheme after responding to several incidents where victims received these unsolicited offers (GuidePoint Security). The messages claimed the sender had spent three years finding vulnerabilities in the administrative panels of ransomware-as-a-service operations and had discovered the victim's data on a recently accessed server. The quoted price for recovering files and destroying the stolen backups: between $20,000 and $60,000. GRIT observed the activity during responses to attacks attributed to DragonForce, Settra, and Anubis. When investigators pressed the group on details, it confirmed access to the exact same dataset the actual ransomware affiliate possessed. GRIT's assessment, with moderate confidence: Ransom Busters is not a rescue service but a single ransomware affiliate working across multiple operations, using its insider position to divert payment discussions away from the gang it works for and pocket the money itself (The Hacker News).

Why the Timing Gives It Away

BleepingComputer's report notes that legitimate security firms do sometimes contact ransomware victims to offer consulting, but only after an attack has become public knowledge through leak sites, filings, or reporting (BleepingComputer). Knowing about an incident while it is still private means either being the attacker, working with the attacker, or reading the attacker's channels. In the ransomware-as-a-service ecosystem, affiliates are exactly the actors with that access: they run the intrusions, know the victim list, and often sit in on negotiations. Negotiation firm Coveware told BleepingComputer it has seen similar self-styled 'middlemen' as far back as 2024, though earlier versions typically approached victims only after public disclosure. Coveware also flagged the practical danger: once a rogue party with access to stolen data inserts itself into the process, paying the original operation no longer guarantees everyone holding copies will honor a non-leak agreement. A promise of data deletion from criminals is unenforceable by definition, and researchers have repeatedly observed groups retaining extra copies for later re-extortion or resale. There is older history here too. ProPublica documented in 2019 how some data recovery firms told breach clients their files would be restored using proprietary technology while quietly paying the ransom themselves and pocketing the markup (ProPublica). Ransom Busters escalates that model: instead of a middleman skimming a percentage, the attacker runs a second extortion directly against the victim of the first.

Red Flags Checklist

GRIT and Dark Reading identified several tells that separate this scam from genuine help (Dark Reading). Any organization facing extortion should treat the following as strong indicators of fraud:
  • Contact arrives while the incident is still private, before any public disclosure.
  • The sender uses a free or privacy-focused email address with no verifiable corporate domain behind it.
  • A fixed price is quoted immediately, before any technical scoping of the incident has taken place.
  • Payment is demanded in Bitcoin or another cryptocurrency, which no credible vendor requests up front for recovery work.
  • The offer includes guaranteed deletion of stolen data, something no third party can technically prove or enforce.
  • The pitch claims to have hacked criminal infrastructure, which would itself be illegal for a legitimate firm to do or admit doing.

What Legitimate Incident Response Looks Like

Real incident response starts with containment and evidence preservation, not a price list. Reputable firms scope the incident first, identify the ransomware strain, check whether a free decryptor already exists through law enforcement-backed resources such as No More Ransom, and only then discuss negotiation options if they are warranted at all. They communicate through verified corporate channels, bill for services rather than demanding crypto transfers, and coordinate with legal counsel and regulators because ransom decisions carry sanctions and disclosure implications that go far beyond file recovery. Legitimate outreach also follows disclosure rather than preceding it. If a message shows knowledge of an attack nobody outside your team should have, that knowledge is itself evidence, and it belongs in front of your IR provider and law enforcement, not in a reply to the sender. Report the contact, preserve the email with full headers, and let professionals assess whether it reveals anything about who attacked you.

The Practical Takeaway

The core defense is procedural, not technical. Decide now, in writing, who is authorized to speak about an incident and that all inbound recovery offers route through them. Treat every unsolicited savior with the same skepticism you would apply to a cold caller asking for credentials, a pattern we covered in our piece on social engineering support scams. Criminals cannot be trusted to honor agreements among themselves, let alone with victims. There are no magic bullets for stolen data, and anyone selling one mid-crisis is most likely selling you a second robbery.

more notes

all news ›