← All research

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

2026-08-25 · OrangeStealth Security

K
Kristen Jarosinski @KJRyan413

#GRIT_Intel’s investigation points to a new twist on ransomware extortion and assesses Ransom Busters to be a ransomware affiliate—not the helpful third party it claims to be. Learn in @GuidePointSec's blog: https://t.co/RavtBZkGI8#ThreatIntel #CybersecurityTip pic.twitter.com/Y0vZs3hAGL

August 26, 2026

If your company ever gets hit by ransomware, the attack itself is only the first bill. A new twist making the rounds shows a second one can follow: someone claiming to be a "fixer" who already has your stolen files and wants tens of thousands of dollars to make them go away — before you've even had a chance to catch your breath.

For a small B2B SaaS company, that second email can look more credible than the first. It arrives quietly, addressed to the CEO, promising to undo the damage. There's no ransom note branding, no countdown timer — just an offer that sounds like relief.

What actually happened

A threat actor calling itself Ransom Busters has been proactively emailing organizations that were already hit by ransomware groups, claiming it hacked into those groups' servers and can delete the victims' stolen data — for a fee of $20,000 to $60,000. The emails go straight to CEOs or IT leadership, and notably arrive before the original attack has become public, which is itself a red flag security researchers flagged as out of the ordinary.

"While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge."
The Hacker News

Researchers who tracked the activity linked it to incidents involving several known ransomware groups, and found the same intrusion toolkit showing up across cases — commodity network scanners, cloud data-exfiltration tools, and remote-management software quietly installed after the initial breach. That consistency suggests Ransom Busters isn't an outside white-hat who stumbled onto stolen data — it looks more like an affiliate working the same breach from a second angle, offering to "fix" a problem it may have helped cause.

Source: The Hacker News

Why this matters to a small B2B SaaS

U
USA NEWS @USANEWS007

News busters show @CNN spent 87 minutes on fake Trump stories last week & 27 sec on 400Mil Ransom #HillarysOlympics pic.twitter.com/pcArIeMzet

August 8, 2016

Picture a 40-person invoicing SaaS that got hit by a ransomware crew three weeks ago. The founder paid a recovery firm, restored from backups, and quietly moved on without telling customers. Then an email lands from a stranger claiming to have found the company's stolen files sitting on the original attacker's own server, offering to delete them for $35,000 — no proof beyond a few filenames, no way to verify the claim, and a payment address that leads nowhere traceable. There's no way to confirm the data still exists, that paying deletes anything, or that a copy isn't already for sale elsewhere. It's the ransom demand again, wearing a helper's face.

The part that should worry a founder most isn't the email itself — it's what it reveals. This scheme only works on companies that already had customer or company data walk out the door in a breach. The email is a second extortion attempt riding on a first compromise that was never locked down properly in the first place.

What to actually do about it

You can't stop someone from emailing you after a breach, but you can make it far less likely there's ever a breach — or stolen data — for a scheme like this to exploit:

  • Treat any unsolicited "we can help" email after an incident as untrusted by default. Verify identity through a channel you initiated, never one the email itself provided, before any reply.
  • Never pay based on a claim alone. "We have your data" with no verifiable proof is a script, not evidence — involve legal counsel and law enforcement before considering any payment.
  • Close the exposures that let data walk out in the first place. Exposed admin panels, forgotten remote-access tools, and internet-facing services with no monitoring are exactly what let an initial breach — and everything that follows it — happen.
  • Know what's reachable from the outside before an attacker or a "fixer" does. Most small SaaS teams have no current inventory of their own external attack surface.
  • Have an incident-response plan written down before you need it, including who verifies claims like this one and who has authority to say no.

OrangeStealth's External Security Posture Assessment gives you a passive, outside-in look at what's actually exposed to the internet today — the gaps that let a first breach happen, before anyone gets the chance to email you about a second one.

K
Kristen Jarosinski @KJRyan413

#GRIT_Intel’s investigation points to a new twist on ransomware extortion and assesses Ransom Busters to be a ransomware affiliate—not the helpful third party it claims to be. Learn in @GuidePointSec's blog: https://t.co/RavtBZkGI8#ThreatIntel #CybersecurityTip pic.twitter.com/Y0vZs3hAGL

August 26, 2026