Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > ‘Ransom Busters’ Demands Up to $60,000 to Recover Ransomware Victims Data

‘Ransom Busters’ Demands Up to $60,000 to Recover Ransomware Victims Data

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 19, 2026

Human Written
‘Ransom Busters’ Demands Up to $60,000 to Recover Ransomware Victims Data
  • Ransom Busters says it broke into ransomware gang servers, then asked victims to pay for their help.

  • The group wants between $20,000 and $60,000 to recover stolen files and erase copies.

  • GuidePoint thinks Ransom Busters is not a rescuer. It may be a ransomware partner turning on its own team.

A group calling itself Ransom Busters has started emailing hacked companies. It claims it broke into ransomware servers first. Then it offers to delete stolen data for a fee. That fee ranges from $20,000 to $60,000.

GuidePoint Research and Intelligence Team (GRIT) studied this odd behavior closely. The team explained that a stranger offering rescue help stands out right away. Cybersecurity firms do reach out to victims sometimes. But they usually wait until news of the attack becomes public first.

How the Scheme Works

GuidePoint has handled several cases tied to this actor. The team believes one person runs the scam. This person likely works as an affiliate across many ransomware groups.

Ransom Busters emails ask to speak with a company’s CEO or top IT staff. The messages claim access to weak spots inside ransomware gang control panels. The sender says they have used this access for over three years.

The message also claims to have found the company’s stolen files. It then asks for payment to unlock systems and delete backup copies. GuidePoint spotted this pattern in cases tied to DragonForce, Settra, and Anubis. A real company acting this way would break U.S. cybercrime law. So GuidePoint says a legitimate firm almost certainly isn’t behind it.

Justin Timothy, a Principal Consultant at GRIT, shared more details. He said the attacker likely hid where their access came from. Or they simply weren’t following any legal rules at all. When asked why they charge money, the group gave a strange answer. They said working for free would put their gang access at risk.

Two separate cases showed matching clues. Both used SoftPerfect Network Scanner to explore infected networks. Also, both used a tool called s5cmd to move stolen files to cloud storage. Both installed remote access software through a script.

Created a hidden account using the same password, “Numlock!123.” Both cases also showed the same attacker computer name. This overlap points to one operator repeating the same playbook.

Timothy warned that criminals cannot be trusted, even by other criminals. He said Ransom Busters, most likely a ransomware affiliate in disguise, betrayed its own partners for profit. Paying this group offers no real guarantee that stolen data gets deleted. Treat any offer like this as a trick, not real help.

Other Ransomware Threats Keep Growing

GuidePoint also tracked a separate group called UNC6671. This group has targeted banks, law firms, and other industries since April. It uses phishing brands named Falcon, Helix, Pink, Redact, and BlackFile. The group focuses on large, valuable targets instead of random victims. GuidePoint said this matches tactics used by groups like Shiny Hunters.

The group has collected more than $8 million from 15 Bitcoin wallets. Researchers found 78 phishing web addresses across 76 companies in 15 industries.

Roughly 40% of these targets work in finance, such as hedge funds and investment firms. The group runs a custom tool that manages calls, targets, and stolen logins. GuidePoint called this setup a major step forward for phone-based scams.

Unverified dark web claims are another growing problem. A threat actor recently advertised what they claimed was a database from Planity, a French beauty and wellness booking platform, offering over one million records for $2,500 in Bitcoin. However, the seller’s account had almost no posting history, and Planity has not confirmed any breach, making the claim a reminder that dark web data sales should be treated with skepticism until independently verified.

The wider ransomware world keeps shifting too. New groups such as Tengu, CRPx0, and Majinahanashi appeared in recent months. Check Point’s newest report counted 2,139 companies listed on leak sites this quarter. The number of active ransomware groups jumped from 71 to 93. In July 2026 alone, gangs claimed 873 new victims. That number rose from 722 victims the month before.

Coveware, owned by Veeam, tracked ransom payments during this period too. The average payment jumped 176% between quarters, reaching $1,880,612. However, the typical middle payment actually dropped to $150,000.

Coveware linked the rise to a few extremely large payouts tied to stolen data cases. One major driver was a law firm targeting a campaign by a group called Silent Ransom.

How to Protect Your Business

Never trust unexpected offers to “recover” your stolen data for a fee. Real cybersecurity help does not usually appear uninvited before news breaks. Report any suspicious rescue emails to your security team right away. Confirm every claim through official channels, not the message itself.

Watch for common attacker tools during network checks, like unknown scanners. Unusual new user accounts on your systems deserve quick investigation too. Train staff to verify caller identity, especially those requesting sensitive account access. Update software and close known access points ransomware groups often exploit.

Remember that paying criminals never guarantees stolen files get deleted. Backups, monitoring, and fast incident response remain your strongest long-term defenses.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.