← Blog · · df00tech

"Ransom Busters" Group Emails Ransomware Victims Offering Paid Data Deletion for $20K–$60K

security-news campaign

What happened

According to The Hacker News, citing research from GuidePoint, a group calling itself "Ransom Busters" has been proactively emailing organizations that were previously hit by ransomware. The group claims to have compromised ransomware operators' own infrastructure and offers to delete the victim's stolen data from those servers in exchange for a fee ranging from $20,000 to $60,000.

GuidePoint researchers flagged the outreach itself as the tell: an unsolicited third party contacting a ransomware victim and offering to broker data deletion is, in their words, immediately anomalous. It is not clear from the reporting whether Ransom Busters' claims of server access are genuine, whether payment actually results in deletion, or whether this is a new extortion angle layered on top of an existing breach rather than a legitimate remediation offer.

Why it matters for defenders

Organizations that have already suffered a ransomware incident are the target audience here, meaning this specifically preys on victims who are already under pressure and may be eager for any path to close out an incident. Paying an unverified third party carries real risk: there is no guarantee of deletion, the payment could fund further criminal activity, and engaging could expose the organization to additional social-engineering or extortion attempts. It also complicates incident response — a second, unverified actor inserting itself into the recovery process muddies attribution, evidence handling, and any law-enforcement engagement.

What defenders should watch for or do now

  • Treat any unsolicited post-incident email offering to delete stolen data for a fee as a probable extortion/fraud attempt, not a legitimate service — do not engage or pay without validating the claim through incident response and legal counsel.
  • If your organization has previously been a ransomware victim, brief IR, legal, and communications teams on this pattern so an incoming "Ransom Busters"-style email is routed to the right people immediately rather than answered directly.
  • Preserve and analyze any such emails (headers, sending infrastructure, wallet addresses if payment is requested) as they may provide threat-intel value even if the claims themselves can't be verified.
  • Coordinate with existing ransomware negotiators or incident responders before any contact, since distinguishing a genuine offer from a secondary extortion attempt is not something to assess unilaterally.

Developing story

This is a net-new report and details are still emerging — there is no confirmed technical evidence in the public reporting about how Ransom Busters allegedly accesses ransomware infrastructure, or whether any victim has paid. We will continue to monitor for updates. Read the original reporting at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.