Published · 5d agoSecurity3 min read
The extortion layer your IR playbook has no page for: 'Ransom Busters' emails victims mid-incident
GuidePoint says the persona offering to delete stolen data for $20,000 to $60,000 is very likely a ransomware affiliate, which makes the rescue fee a second payment to the same attacker.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A ransomware affiliate calling itself Ransom Busters has been proactively emailing victim organizations, claiming it will delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
- GuidePoint said it has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations.
- The report was produced by GuidePoint Research and Intelligence Team (GRIT) and shared with The Hacker News.
- In emails to victims, Ransom Busters requests contact with their CEO or IT leadership, claims to have found vulnerabilities in administrative panels maintained by RaaS groups, and claims to have been breaking into the servers for over three years.
- The actor claims it found data stolen from the company on one of the servers it recently accessed, and asks for a payment between $20,000 and $60,000 to help the victim regain access to files and data and delete all backups held by the ransomware group.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A threat actor calling itself Ransom Busters has been emailing organisations during live ransomware incidents, claiming it has broken into ransomware groups' servers and offering to delete the victim's stolen data for a fee between $20,000 and $60,000 [1]. GuidePoint's Research and Intelligence Team (GRIT) assesses that the persona is very likely a ransomware affiliate with work across multiple ransomware-as-a-service operations, which means the helpful stranger in the inbox is probably being paid by the victim twice [2] [3].
The pitch is specific. The emails ask to be put in touch with the CEO or IT leadership, claim the sender found vulnerabilities in the administrative panels that RaaS groups maintain, and claim more than three years of access to those servers [4]. The sender then says it located the company's stolen data on a server it recently accessed and asks for payment to help the victim regain access to files and to delete all backups held by the ransomware group [5]. GRIT called the contact anomalous on timing alone: security firms do solicit ransomware victims, but generally only after an attack is public [6].
That routing around the incident response channel and straight to executives is the part most playbooks do not anticipate. GRIT says it saw the same approach while responding to incidents involving DragonForce, Settra and Anubis [7], and that a legitimate company doing this is extremely unlikely because it would violate the U.S. Computer Fraud and Abuse Act [8]. "This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law," said Justin Timothy, a principal consultant at GRIT [9]. Asked why they charged, the group said that working for free would put their access to the threat actor's infrastructure at risk [10].
The forensics point the same direction. Across two incidents, GRIT found overlapping tooling: SoftPerfect Network Scanner for internal reconnaissance, s5cmd to exfiltrate data to AWS cloud storage, and the Remotely RMM tool installed via a PowerShell script [11]. Both intrusions also featured a local backdoor account with the password "Numlock!123" and the same attacker-controlled hostname, DESKTOP-BBETH6K [12], which GRIT says raises the likelihood that a single operator, most likely an affiliate rather than a third party, is behind the activity [13]. Timothy's conclusion is that the persona will betray its own criminal partners for money, that payment to any criminal party offers no guarantee of deletion, and that Ransom Busters should be treated as a hoax [14] [15].
Note the pricing. GRIT frames this as an attempt to encourage more limited extortion payments [16], and the numbers support that reading: in the same reporting, GuidePoint attributes more than $8 million in payments across 15 Bitcoin wallets to five extortion brands run by UNC6671, at an average extortion amount of $600,000 [17]. A $60,000 ceiling is a tenth of that average [18], which is close to the price of a rounding error in a board update and well inside a discretionary spend.
What to watch: whether the persona shows up alongside RaaS families beyond DragonForce, Settra and Anubis [7], and whether the DESKTOP-BBETH6K and "Numlock!123" artefacts appear in unrelated engagements [12], which would argue for one operator rather than a technique being copied. On the defensive side, the practical control is procedural rather than technical: a written rule that unsolicited mid-incident contact goes to counsel and the IR lead, not to the CEO, since the CEO is exactly who the sender asks for [4].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A ransomware affiliate calling itself Ransom Busters has been proactively emailing victim organizations, claiming it will delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
ReportedView cited source - [2]
GuidePoint said it has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations.
ReportedView cited source - [3]
The report was produced by GuidePoint Research and Intelligence Team (GRIT) and shared with The Hacker News.
ReportedView cited source - [4]
In emails to victims, Ransom Busters requests contact with their CEO or IT leadership, claims to have found vulnerabilities in administrative panels maintained by RaaS groups, and claims to have been breaking into the servers for over three years.
ReportedView cited source - [5]
The actor claims it found data stolen from the company on one of the servers it recently accessed, and asks for a payment between $20,000 and $60,000 to help the victim regain access to files and data and delete all backups held by the ransomware group.
ReportedView cited source - [6]
GRIT said the third-party offer of help immediately stands out as anomalous, because while cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- guidepointsecurity.com4d agoGuidePoint Security
- bleepingcomputer.comLawrence Abrams3d agoRogue ransomware affiliate poses as recovery firm to steal payments



