Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

Ransomware Affiliate Poses as Data Recovery Service

A ransomware affiliate calling itself Ransom Busters is emailing victims and offering to delete their stolen data from ransomware groups' servers for fees of $20,000 to $60,000.

Ransomware Affiliate Poses as Data Recovery Service
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·2 min read

New wrinkle in the ransomware extortion ecosystem. GuidePoint Research reports that a ransomware affiliate calling itself Ransom Busters is proactively emailing victim organizations and offering to delete their stolen data from ransomware groups’ servers — for a fee ranging from $20,000 to $60,000.

The actual goal: divert ransom payments away from the primary ransomware operator and into their own pocket.

How It Works

Ransom Busters contacts victims directly. The pitch: they’ve accessed the ransomware group’s infrastructure, they can delete the stolen data, and they’ll do it for a flat fee. GuidePoint characterizes the approach as “anomalous” — this kind of proactive third-party contact is not standard ransomware affiliate behavior.

What’s actually happening: this is a second-order extortion play layered on top of an existing ransomware incident. Victims are being targeted twice — once by the original operator, and again by a sub-affiliate angling for a separate payout.

Whether Ransom Busters actually has access to the primary group’s exfil servers — unconfirmed. The offer to delete data is unverifiable. Paying does not guarantee deletion and would not be confirmed by any legitimate party.

Confidence Table

Claim Confidence
Ransom Busters sending unsolicited emails to victims Confirmed — GuidePoint Research
Fees of $20,000–$60,000 demanded Confirmed — GuidePoint Research
Goal: divert ransom payments from primary operator Assessed — GuidePoint Research
Actual access to primary group’s servers Unconfirmed
Data deletion guarantee Unverifiable

What to Do If You Receive Contact

Do not pay. Do not engage without counsel and incident response guidance. GuidePoint’s finding should be shared with your IR team as IOC context for any active ransomware incident.

This is social engineering layered onto an already-active intrusion. The existence of Ransom Busters contact does not mean:

  • Your data is safely accessible to a third party
  • Payment will result in deletion
  • The offer has any legal or operational validity

Contact from Ransom Busters may also signal that the original ransomware operator has loose enough affiliate controls that sub-actors can identify and contact victims independently — itself worth noting in any attribution or negotiations strategy.

Found this useful? Share it.