Until now, ransomware attacks have primarily been associated with cybercriminals infiltrating the networks of public and private organizations, encrypting critical files, and demanding a ransom in exchange for restoring access to the affected data. In recent years, these attacks have become even more aggressive, with several criminal groups adopting double- and triple-extortion tactics to put additional pressure on victims. Apart from encrypting data, attackers may threaten to leak stolen information, disrupt operations, or contact customers and business partners if the ransom is not paid.
However, a new tactic has emerged that adds another layer of deception to the already complex ransomware ecosystem. Cybercriminals are now attempting to exploit ransomware victims by pretending to be a separate group capable of undoing the damage caused by the original attackers.
According to an research update from the GuidePoint Research and Intelligence Team (GRIT), a group calling itself “Ransom Busters” has been contacting ransomware victims through email. The group claims that it has infiltrated the infrastructure of another criminal organization involved in malware distribution and has obtained access to data belonging to ransomware victims.
The alleged group tells victims that it possesses copies of the data stolen during the original ransomware attack and offers to permanently delete that information from the criminals’ servers in exchange for a relatively small payment. In some cases, the group also claims to have obtained the decryption keys required to unlock encrypted files. Victims are then asked to pay amounts reportedly ranging from $20,000 to $60,000 for access to those keys.
Ransom Busters has reportedly claimed possession of stolen victim data associated with ransomware groups such as DragonForce, Settra, and Anubis. The group allegedly promises to delete the stolen information if victims agree to its financial demands.
What makes this tactic particularly concerning is the timing. According to GRIT researchers, these communications can reach victims even before the original ransomware operators publicly identify the victim or disclose the attack. This creates additional confusion for organizations already dealing with a serious cybersecurity incident, while there is no guarantee that paying the new claimant will result in data deletion or recovery of encrypted files.
GuidePoint researchers believe the activity could potentially involve a ransomware affiliate or another actor with connections to multiple cybercriminal groups. The objective may be either to divert victims away from negotiating with the original ransomware operators or to secure a portion of the ransom money for themselves.
Regardless of the exact motive, victims could suffer further financial losses by responding to such demands. Organizations should therefore avoid making hurried payments based solely on unsolicited claims of possessing decryption keys or stolen data.
Instead, victims should immediately involve law-enforcement authorities, incident-response teams, and trusted cybersecurity and forensic experts. Law-enforcement agencies may be able to track the criminals and contribute to disrupting or dismantling their infrastructure, while cybersecurity specialists can investigate the intrusion, determine what information was compromised, and assist with recovery.
As ransomware tactics continue to evolve, organizations must recognize that the attackers may not always be the only ones attempting to profit from an incident. Fake “ransom busters” demonstrate how cybercriminals can exploit the uncertainty and urgency surrounding ransomware attacks, making professional incident response and independent verification more important than ever.
