Fake "Ransom Busters" Recovery Firm Is a Ransomware Affiliate in Disguise
BleepingComputer reports that a suspected ransomware affiliate is impersonating a data-recovery service calling itself "Ransom Busters." According to the report, the actor contacts victims before an attack is publicly disclosed, posing as a legitimate recovery firm and offering to supply decryption keys and delete stolen data — for a fee. Full technical details of the scheme and its targets have not yet been published.
Why It Matters
This tactic blurs the line between extortion and "recovery," giving the threat actor a second monetization channel and a way to pressure victims outside normal ransom-note workflows. Because the outreach reportedly happens before an attack becomes public, it suggests the impersonator has early knowledge of victim status — consistent with the actor being the affiliate behind the intrusion itself, or closely coordinated with them. Organizations engaging with unsolicited "recovery" offers risk paying a second time, negotiating with the very group that attacked them under a false identity, or having sensitive breach details confirmed to an unverified party.
What Defenders Should Watch For
- Unsolicited outbound contact (email, phone, portal messages) from a "recovery firm" referencing incident details that have not been made public — this is a strong signal of insider knowledge or affiliate involvement.
- Verify the identity and legitimacy of any recovery/negotiation firm through independent, out-of-band channels before any engagement or payment.
- Treat claims of stolen-data deletion with skepticism; there is no reliable way to confirm deletion, and paying does not guarantee compliance.
- Loop in legal counsel and law enforcement before any communication with parties claiming access to decryption keys or exfiltrated data.
- Preserve any communications from self-proclaimed recovery services as potential threat-actor artifacts for incident response and attribution.
This is developing, net-new intelligence based on a single report and details may evolve as more information emerges. Read the original coverage from BleepingComputer: Rogue ransomware affiliate poses as recovery firm to steal payments.