Ransomware Affiliate Poses as Data Recovery Service
A ransomware affiliate calling itself Ransom Busters is emailing victims and offering to delete their stolen data from ransomware groups' servers for fees of $20,000 to $60,000.

New wrinkle in the ransomware extortion ecosystem. GuidePoint Research reports that a ransomware affiliate calling itself Ransom Busters is proactively emailing victim organizations and offering to delete their stolen data from ransomware groups’ servers — for a fee ranging from $20,000 to $60,000.
The actual goal: divert ransom payments away from the primary ransomware operator and into their own pocket.
How It Works
Ransom Busters contacts victims directly. The pitch: they’ve accessed the ransomware group’s infrastructure, they can delete the stolen data, and they’ll do it for a flat fee. GuidePoint characterizes the approach as “anomalous” — this kind of proactive third-party contact is not standard ransomware affiliate behavior.
What’s actually happening: this is a second-order extortion play layered on top of an existing ransomware incident. Victims are being targeted twice — once by the original operator, and again by a sub-affiliate angling for a separate payout.
Whether Ransom Busters actually has access to the primary group’s exfil servers — unconfirmed. The offer to delete data is unverifiable. Paying does not guarantee deletion and would not be confirmed by any legitimate party.
Confidence Table
| Claim | Confidence |
|---|---|
| Ransom Busters sending unsolicited emails to victims | Confirmed — GuidePoint Research |
| Fees of $20,000–$60,000 demanded | Confirmed — GuidePoint Research |
| Goal: divert ransom payments from primary operator | Assessed — GuidePoint Research |
| Actual access to primary group’s servers | Unconfirmed |
| Data deletion guarantee | Unverifiable |
What to Do If You Receive Contact
Do not pay. Do not engage without counsel and incident response guidance. GuidePoint’s finding should be shared with your IR team as IOC context for any active ransomware incident.
This is social engineering layered onto an already-active intrusion. The existence of Ransom Busters contact does not mean:
- Your data is safely accessible to a third party
- Payment will result in deletion
- The offer has any legal or operational validity
Contact from Ransom Busters may also signal that the original ransomware operator has loose enough affiliate controls that sub-actors can identify and contact victims independently — itself worth noting in any attribution or negotiations strategy.
Related Coverage
- Medusa Ransomware Hits 500+ Victims, CISA Updates Advisory — latest CISA/FBI ransomware advisory
- Clop Built Custom Webshell for Windchill Data Theft — ransomware affiliate tooling
- Windows Task Host Vuln Used in Active Ransomware Campaigns — KEV-tracked ransomware exploitation
Found this useful? Share it.


