⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Ransom Busters Scam Targets Ransomware Victims with Fake Data Deletion Services

August 18, 2026

A threat actor calling itself ‘Ransom Busters’ is targeting ransomware victims with a novel extortion scheme, offering to delete stolen data from ransomware servers for a fee of $20,000 to $60,000. According to a report from GuidePoint Research and Intelligence Team (GRIT), the group sends unsolicited emails to victims, claiming to have breached the infrastructure of ransomware-as-a-service (RaaS) operations and found the victim’s stolen data. They request contact with CEOs or IT leadership and demand payment to delete the data and backups.

GRIT observed this activity while responding to incidents involving ransomware groups such as DragonForce, Settra, and Anubis. The cybersecurity firm notes that the approach is highly anomalous, as legitimate security firms typically only contact victims after an attack becomes public. The group’s explanation for charging a fee—claiming that acting without compensation would jeopardize their access—is unconvincing and likely a pretext for further criminal profit.

Analysis of two incidents revealed striking similarities, including the use of SoftPerfect Network Scanner for reconnaissance, s5cmd for data exfiltration to cloud storage, and a remote monitoring and management (RMM) tool called Remotely, installed via PowerShell. Both intrusions also involved the creation of a local backdoor account with the password ‘Numlock!123’ and the same attacker-controlled hostname, DESKTOP-BBETH6K. This suggests a single operator, likely a ransomware affiliate, is behind the ‘Ransom Busters’ persona.

GRIT warns that paying such criminals offers no guarantee of data deletion and that the group is willing to betray even its criminal partners for financial gain. The disclosure coincides with other ransomware trends, including the rise of new groups like Tengu, CRPx0, and Majinahanashi, and a surge in average ransom payments to $1.88 million in Q2 2026, driven by data exfiltration-focused extortion campaigns.

Attack groups: Ransom Busters, DragonForce, Settra, Anubis, UNC6671, Cordial Spider, Falcon, Helix, Pink, Redact, BlackFile, Tengu

Malware: Remotely, SoftPerfect Network Scanner, s5cmd

Companies: GuidePoint Research and Intelligence Team, Okta, Bitdefender, Huntress, Coveware, Veeam, Check Point, CYFIRMA, SonicWall

Products: Work Panel, Microsoft 365