Skip to content

‘Ransom Busters’: Ransomware Actor Poses as Incident-Recovery Service

August 18, 2026 – Published on Dark Reading

A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model.

According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as “Ransom Busters” has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters “can return your files to you and destroy all backups held by the group.” The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files.

However, there are multiple red flags behind the purported offer of help, Justin Timothy, principal threat intelligence consultant at GuidePoint Security, explained. For one, in the cases GRIT observed, Ransom Busters reached out before the ransomware attack became public knowledge; incident-response firms usually offer their services after an attack is disclosed.

Ransom Busters also claims in its communications to have accessed the administrative panel of ransomware-as-a-service (RaaS) actors. Offensive actions from a third party, Timothy noted, could be considered a violation of the US government’s Computer Fraud Abuse Act.

Read More HERE.