GuidePoint Security's research team answered the emails, and published what it found: an outfit calling itself Ransom Busters LTD, which contacts ransomware victims before their incident is public and offers to delete their stolen data for a fee, is in GRIT's assessment a ransomware affiliate that has resorted to an alternate extortion technique, with the same financial motivation as the RaaS groups it claims to be fighting [1][3]. That assessment matters less as attribution than as a procurement problem: the offer lands at the exact moment a victim can verify least and spend fastest.
The pitch is well built. Victim organisations received email at their domain addresses asking to be put in touch with the CEO or IT leadership [4]. The body told them the sender represented a project that assists victims of cyberattacks, had spent over three years identifying vulnerabilities and infiltrating the servers of criminal groups, had found the victim's stolen data on a server it recently accessed, could return the files and destroy all backups the group held, and had obtained access to the encryption key storage [5]. In follow-up messages the actor claimed to have found vulnerabilities in the administrative panels of several ransomware-as-a-service operations, the backend portals through which those businesses run, and said this gave it control over "almost all of their infrastructure" [6].
GRIT's first tell was calendar, not code. Security firms do solicit ransomware victims, but generally only after an incident becomes public knowledge; here the outreach preceded publicity, which raises the question of how Ransom Busters knew about the incident at all [2]. The second tell was legal. Unauthorised access to a RaaS operation's servers to delete data could itself be a violation of the Computer Fraud and Abuse Act, and GuidePoint notes it would not expect a legitimate organisation to potentially commit a crime, still less to charge a fee for doing so [10]. Asked why the help cost money, the group said that acting without compensation would put its access to the threat actor's infrastructure at risk, an explanation GuidePoint found difficult to accept because payment has no logical bearing on the group's ability to reach criminal infrastructure [11].
The evidence that closes the loop
Two things in GRIT's account move this from suspicion to something a negotiator can act on. First, when questioned, Ransom Busters confirmed access to the exact same dataset the ransomware affiliate possessed [8]. Second, GuidePoint's DFIR team worked two incidents where Ransom Busters made contact, and forensic analysis of both environments showed overlapping tooling: SoftPerfect Network Scanner for internal reconnaissance, s5cmd to push data to cloud storage via AWS, and the Remotely RMM tool installed through a PowerShell script [12]. GuidePoint's reasoning is that while ransomware intrusions follow similar playbooks, individual attacks tend to have their own signature in tooling and persistence, and actors have several options for each of those tasks, which makes identical selections across two environments meaningful [13].
Read those together and the "we hacked the hackers" story collapses into the simpler one. The party offering to delete your data is demonstrating possession of your data, which is the only thing either side of a data extortion actually trades.
Counting the brands a victim may meet is then instructive. GRIT observed the Ransom Busters behaviour while responding to incidents from threat groups including DragonForce, Settra and Anubis [7]. Add the recovery persona to the three ransomware names and at least four brands attach to one body of activity, which is the practical reason a victim cannot treat a second email as a second opinion [1]. The fee, incidentally, is not a mystery to be discovered under pressure: the group offered to delete stolen data for between 20,000 and 60,000 dollars [9]. That is a band you can set a policy against in advance rather than a number you discover at 2am.
Why the vulnerability never comes up
The reason this model works is that the front door has not moved. Beazley Security's second-quarter 2026 report counts more than 20,700 newly disclosed vulnerabilities, a 36 per cent increase, while confirmed exploitation in the wild grew by just 10 per cent [14]. Against that, 67 per cent of ransomware intrusions in the quarter started with compromised credentials against exposed VPN and RDP, with SEO-poisoned installers accounting for another 14 per cent [15]. An extortion business built on credentials does not need a CVE, a patch window, or an exploit developer.
It increasingly does not need encryption either. Beazley reports a growing share of affiliates skipped encryption entirely in the quarter in favour of pure data theft and extortion, a pattern it saw from Inc Ransomware, Brain Cipher and Pear affiliates [16]. On the Srsly Risky Biz podcast, Tom Uren and James Wilson made the demand-side version of the same point: for organisations whose reputation matters to them, a data leak is a bigger threat than having files locked [39]. Drop encryption and you drop the noisiest, most detectable, most recoverable part of the operation while keeping the part victims actually pay for.
The credential supply keeps arriving through channels that have nothing to do with your perimeter. Beazley describes attackers abusing Microsoft's device code sign-in flow to get past MFA: the attacker generates a code, the victim enters it on a genuine Microsoft sign-in page, the login and MFA are real, nothing looks wrong, and the attacker collects the session token [17]. Further upstream, OpenSourceMalware reported on 15 August 2026 a set of newly published RubyGems typosquats installing a multi-stage Windows infostealer that harvests browser credentials, crypto wallets, seed phrases and Telegram data, reaching hundreds of downloads before takedown [21]. Its notable design choice, in the researchers' account, is that the loader and browser-injection DLL are encrypted inside earlier stages rather than fetched from further URLs, with an embedded DLL to extract the ABE key modern Chromium builds use to protect saved passwords and cookies, so there is no second-stage download and no payload C2 for network defenders to catch after the first request [22]. Enforcement dents this market without closing it: Beazley credits Operation ENDGAME actions against First VPN, SocGholish, Amadey and StealC with a measurable drop in activity from May with no arrests announced, but the StealC operator shipped a new build within four days and offered the old source code for sale at 60,000 dollars, while LummaStealer is attempting a return as Remus [20].
Where a vulnerability does feature, the aftermath looks familiar. SafePal is notifying roughly 40,000 people, 39,798 customers by its own count, after attackers exploited a flaw in the order-tracking function of a customer order information plugin [23]. The exposed fields are names, addresses, email addresses, phone numbers and order details for orders placed between 2 March 2025 and 11 April 2026, and the company says seed phrases, private keys, wallet credentials, bank details, card numbers and government ID numbers were not involved [24]. SecurityWeek notes SafePal disclosed on the same day a threat actor began advertising the data on a cybercrime forum, with the seller claiming the same 39,798 figure [26]. The number matching on both sides of that transaction is the same verification signal GRIT used, from the other direction.
The list now includes the machines that keep buildings running
Medical and clinical data has moved into this economy in two distinct forms, and neither of the incidents below is connected by the sources to Ransom Busters. Baylor Genetics says it identified suspicious activity on or around 15 June 2026, determined an unauthorised third party accessed parts of its network and certain data between 11 and 17 June, and completed its review of what was involved on or about 30 July [28]. The company says patient information may have included names plus date of birth, medical testing information, laboratory test results, potentially health insurance information, and Social Security numbers for a very limited subset, while employee data may have included Social Security numbers, government-issued identification numbers and financial account information [29]. Risky Bulletin notes the company did not disclose how many individuals were affected [31]. That combination, a completed review and no count, is the version of disclosure a data extortion crew has the most leverage over.
The Winnipeg case shows the other form. Shared Health says ransomware hit maintenance systems at the Health Sciences Centre and Cancer Care Manitoba without affecting patient care [32], that central monitoring of heating, ventilation and cooling was affected though the systems still run and are monitored locally, and that the site's security office is closed and the hospital cannot issue or update ID access cards [33]. The problem was discovered on 10 August 2026, extra on-site security was added as a precaution, and a week later the hospital was still recovering while Shared Health continued to investigate whether personal health or financial data was accessed, with an initial review suggesting none was [34]. Healthcare also sits on the hiring-side target list: Recorded Future's Insikt Group says one PurpleDelta cluster, its designation for North Korean IT workers, applied to over 1,100 companies between late 2024 and early 2025, primarily in software and technology, staffing and consulting, and healthcare and biotechnology, using at least 22 fabricated personas and probably reaching active employment at ten or more organisations [35].
The cost of not having a verification policy
Two public-sector incidents this week show what the unanswered question costs. In Berlin, a cyberattack disrupted the Senate departments for urban development, building and housing and for mobility, transport, environment and climate protection, both disconnected from the state Landesnetz on the Friday as a precaution [40]. Tagesspiegel reports the specialist system covering housing entitlement certificates, misuse of housing and Wohngeld is completely paralysed, putting at risk payments to the more than 50,000 eligible households and the Bildung und Teilhabe benefit [41]. On what left the network, the accounts diverge in public: the Senate chancellery says forensic work detected a compromise of the state network, and spokeswoman Christine Richter told Tagesspiegel that on current knowledge no sensitive data flowed out and the data concerned was freely available open data, contradicting an RBB report that sensitive data was taken, while a person familiar with events told the paper data did leave but consisted of geoinformation also retrievable from a public database, and that it is being examined whether the known incident served to distract from another attack [42]. UT San Antonio, by contrast, took systems offline proactively after attempted unauthorised activity was detected at its network edge, delayed the start of fall classes by three days to Monday 24 August, and says its investigation has found no evidence university data was accessed or exfiltrated [44].
The housekeeping continues in parallel and should be understood as housekeeping. Microsoft says that from August 2026 Windows 11 versions 24H2 and 25H2 no longer include the WMIC utility and it is no longer available as a Feature on Demand [37]. WMIC is a signed Microsoft binary abused by attackers to identify installed antivirus and remove security software, and Microsoft deprecated it in Windows 10 21H1 in 2021, converted it to a Feature on Demand in 22H2, and disabled it by default in Windows 11 25H2 [38]. Removing one living-off-the-land binary after five years of staging is worth having. It does not touch exposed VPN and RDP with stolen credentials.
What to watch is narrow and operational. Whether Ransom Busters, or the next persona, appears alongside RaaS brands beyond DragonForce, Settra and Anubis [7], and whether the 20,000 to 60,000 dollar band holds as the offer scales [9]. Whether Baylor Genetics eventually publishes an affected-individual count [31], because a number that appears first on a forum, as it did with SafePal [26], is a number someone else set. And whether the Berlin dispute over what left the Landesnetz resolves toward the chancellery's account or RBB's [42], since that is the same question every victim of a pure-exfiltration crew has to answer under a deadline.