A ransomware affiliate operating under the name Ransom Busters has launched an unusual extortion scheme targeting organizations hit by ransomware attacks. The group sends unsolicited emails to victim organizations claiming to have breached ransomware gang servers and offering to delete stolen data for fees between $20,000 and $60,000.
The pitch exploits victim desperation. Organizations facing data theft threats from established ransomware operations receive credible-looking offers from Ransom Busters, who claim access to the attackers' infrastructure. The emails position the group as a solution provider rather than threat actors, creating confusion about who actually holds the data.
Security researchers at GuidePoint Research flagged this approach as anomalous. The proactive contact pattern differs from standard ransomware operations, which typically wait for victims to discover breaches before demanding payment. Ransom Busters initiates contact, suggesting either genuine server access or a sophisticated social engineering campaign designed to extract money from panicked security teams.
The scheme presents multiple risks. Victims paying Ransom Busters have no guarantee the group actually possesses data deletion capabilities or access to ransomware infrastructure. Organizations may pay the extortion fee without receiving any benefit. Additionally, engaging with the group creates a new financial trail and potentially signals to other threat actors that the victim organization possesses available funds.
The affiliate's claims remain unverified. Whether Ransom Busters genuinely compromised ransomware gang servers or operates as a confidence scheme remains unclear. Either scenario poses organizational risk. If legitimate access exists, victims face pressure to pay before establishing whether stolen data actually exists on targeted systems. If fraudulent, victims lose money while their original ransomware threat remains unresolved.
Organizations should treat these solicitations as potential extortion attempts. Legitimate incident response requires contacting established cybersecurity firms and law enforcement rather than engaging with uns
