The Ransom Busters scam is rewriting the rules of ransomware negotiations in a way few victims see coming. Ransomware has always had a predictable, if brutal, script: attackers encrypt your data, demand payment, and threaten to leak what they’ve stolen if you don’t pay. Victims know the players involved. What they don’t expect is a third party inserting itself into the middle of the negotiation—one that turns out to be working both sides. That’s exactly what researchers just uncovered, and it’s a development worth every business owner’s attention.
A “Recovery Firm” That Knew Too Much
Security researchers at GuidePoint Security’s Research and Intelligence Team (GRIT) identified a group calling itself “Ransom Busters” that has been contacting ransomware victims and offering, for a fee ranging from $20,000 to $60,000, to hand over decryption keys and delete stolen data.
On the surface, that might sound like a legitimate—if opportunistic—recovery service. Here’s the problem: Ransom Busters was reaching out to victims before their attacks had become public. There was no data leak site post, no public disclosure, no way for an outside party to have known an attack had even happened. Yet somehow, Ransom Busters knew. This early contact is one of the clearest red flags in the Ransom Busters scam.
The Twist: The “Recovery Firm” Is Likely the Attacker
That detail set off alarm bells, and the investigation that followed uncovered something far more troubling than an opportunistic scammer. Researchers found that in separate incidents, the intrusions traced back to Ransom Busters used identical tools, including SoftPerfect Network Scanner and a remote monitoring utility, plus the exact same backdoor password and the same attacker-controlled hostname.
That kind of overlap doesn’t happen by coincidence. GRIT now believes, with moderate confidence, that Ransom Busters isn’t a recovery firm or an outside opportunist at all—it’s a ransomware affiliate. In other words, the “helpful third party” offering to sell victims their own decryption keys is very likely the same actor who broke in and stole the data in the first place, now trying to collect a second payday by cutting out the ransomware operation it works for.
A ransomware negotiation firm, Coveware, told BleepingComputer it has responded to similar incidents involving the same actor, and noted that this kind of interference before an attack becomes public is far more concerning than the more familiar “ambulance chasers” who approach already-public victims after the fact. The Ransom Busters scam exploits the chaos of an active incident by inserting itself before the victim has even had time to mobilize a proper response team.
Why This Changes the Math for Victims
This discovery matters because it undermines one of the few things victims could previously count on in a ransomware negotiation: a predictable, if illegitimate, chain of custody. If you pay a ransomware group, the assumption has always been that everyone with access to your stolen data is bound by whatever assurances come with that payment.
Ransom Busters breaks that assumption. If a rogue affiliate has independently copied stolen data and is operating outside the ransomware group’s own agreements, paying the “official” ransom no longer guarantees that everyone who touched your data will honor a promise not to leak it. Researchers point to growing distrust within ransomware-as-a-service operations as a likely driver—affiliates looking to squeeze extra profit out of victims beyond their normal cut from the group they work with. The Ransom Busters scam shows how internal friction among cybercriminals can create new risks for the organizations they target.
What Businesses Should Take Away From This
Whether or not your organization has ever dealt directly with a ransomware attack, this story reinforces a few things every business should keep in mind:
- Never engage independently with anyone claiming to offer ransomware recovery or negotiation services, especially if they contact you before an incident has been made public. Legitimate incident response should go through your security provider, legal counsel, and—if involved—law enforcement, not a party that reaches out to you unsolicited.
- A ransom payment was never a guarantee, and this makes that truer than ever. Paying does not reliably ensure data won’t be leaked or resold, by the original attacker or by someone else with a copy.
- The best defense is still prevention. None of this matters if the initial compromise never happens. The tools used in these attacks—network scanners, remote monitoring software, backdoor accounts—are the same categories of tools a strong endpoint detection and monitoring program is built to catch early.
- Have an incident response plan and partner in place before you need one. In the chaos of an active ransomware incident, having a trusted security partner already identified means you’re not vulnerable to being contacted and manipulated by opportunistic (or actively malicious) third parties.
Recognizing the patterns of the Ransom Busters scam early can help organizations avoid a second financial hit on top of an already damaging breach. Clear internal policies that prohibit employees from responding to unsolicited recovery offers are a practical first step.
The Bottom Line
Ransomware negotiations were already high-stakes and murky. Now there’s evidence that even the criminals can’t fully trust each other—and that instability is spilling over onto victims in the form of new scams layered on top of the original attack. The Ransom Busters scam is a clear example of how affiliates may try to monetize stolen data twice. The safest position, as always, is to never be in the position to negotiate in the first place: strong prevention, continuous monitoring, and a response plan that doesn’t leave room for a rogue third party to insert themselves into your worst day.
Want to know if your organization is prepared for a ransomware incident before it happens? Contact Black Belt Secure to talk through your incident response readiness.
