🚨 Fake "Ransom Busters" Recovery Firm Is Actually the Hacker
Thursday, 20 August 2026
Security researchers have uncovered a nasty twist on ransomware: a suspected hacker is posing as a ransomware recovery company called "Ransom Busters", contacting victims before their attack is even public and offering to fix everything — for a hefty fee.
According to GuidePoint Security's threat intelligence team (GRIT), the group contacted victims of recent ransomware attacks offering decryption keys and "deletion" of stolen data for between $20,000 and $60,000. The catch? The evidence suggests Ransom Busters is very likely the same criminal behind the attacks in the first place.
How the scam works
- A business gets hit by ransomware. Files are locked, data is stolen, and the pressure is on.
- Out of nowhere, "Ransom Busters" emails the victim — before the attack has been publicly disclosed anywhere. That's the first red flag: how would an outside company know?
- They claim to have "inside access" to the ransomware gang's systems, offering to decrypt files and delete stolen data for a five or six-figure fee.
- The victim pays — or doesn't. Researchers say the "recovery firm" appears to be the affiliate behind the attack, skimming extra profit from victims on top of what the ransomware gang itself demands.
Why researchers are confident it's the attacker
GRIT compared two incidents and found the same software, the same hacking tactics, the same local backdoor account (password Numlock!123), and the same attacker-controlled hostname (DESKTOP-BBETH6K). They believe, with moderate confidence, that Ransom Busters is a single ransomware affiliate using its access to steal ransom payments from the very gangs it works with.
Even worse: ransomware negotiation firm Coveware confirmed it has seen similar "middlemen" since 2024 — but contacting victims of non-public incidents is a more dangerous escalation. It means paying the real ransomware gang may no longer guarantee your stolen data stays private, because a rogue third party also has a copy.
What this means for UK families and businesses
Ransomware is a growing threat to UK small businesses, schools, charities, and even households. This scam adds a second layer of danger: after an attack, desperate victims may be approached by "helpers" who are actually making things worse.
The golden rule: never pay a ransom, and never pay an unsolicited "recovery" firm. No legitimate company can magically know about a private attack, and paying criminals — of any kind — only funds more crime and guarantees nothing.
Your family & business safety checklist
- Don't pay unsolicited "recovery" services. If someone contacts you offering to decrypt files or delete stolen data for a fee, treat it as a scam — especially if the offer arrives before the attack is public.
- Use only vetted professionals. If you need ransomware help, go through your insurer, a recognised cyber security provider, or the NCSC's Incident Management team — never a cold caller or cold email.
- Back up, back up, back up. Keep offline or cloud backups with versioning so you can restore files without ever paying anyone.
- Patch and update. Many ransomware attacks start with unpatched software or weak passwords. Enable automatic updates and use multi-factor authentication everywhere.
- Report it. If you or your business is hit, report to Action Fraud at actionfraud.police.uk or on 0300 123 2040. Small businesses can also contact the NCSC.
- Don't be ashamed. Ransomware criminals are professionals who target anyone. Reporting early helps stop the next victim.
The bottom line
When a "recovery firm" you've never heard of emails you out of the blue, offers to fix a hack you haven't told anyone about, and asks for $20,000+ — that's not a rescue. That's the attacker trying to get paid twice.
— CyberAware UK · 🐾 GUARDED BY BULLY — DIGITAL THREAT RESPONSE UNIT
