Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
August 18, 2026 – Published on The Hacker News
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.
“In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,” GuidePoint Research and Intelligence Team (GRIT) said in a report shared with The Hacker News. “While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge.”
The cybersecurity company said it has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations.
In emails sent to the victims, Ransom Busters is seen requesting contact with their CEO or IT leadership, while claiming to have found vulnerabilities in administrative panels maintained by RaaS groups and breaking into the servers for over three years.
Read More HERE.