An entity calling itself Ransom Busters emails organizations during an active attack, offering to retrieve their files from the criminals who took them.
What happened
Researchers investigating ransomware incidents have identified an operation styling itself "Ransom Busters" that contacts victims, claiming to have broken into the servers of multiple criminal groups and found data belonging to that organization, Dark Reading reported on August 18, 2026. For a fee of between $20,000 and $60,000, the emails offer to return the victim's files, destroy all backups the ransomware group holds, and hand over encryption keys. The behavior surfaced during responses to incidents involving DragonForce, Settra, and Anubis, with the sender claiming its access covered almost all of those groups' infrastructure. Questioned by responders, Ransom Busters confirmed access to the exact dataset the ransomware affiliate held.
Going deeper
Two incidents where victims received these emails carried nearly identical technical fingerprints. Investigators found overlapping tooling for internal reconnaissance, data exfiltration, and remote monitoring and management, local backdoor accounts sharing a single password, and the same attacker-controlled hostname appearing across both intrusions. Attacks normally differ from one another in tooling and persistence methods even when they share broad characteristics, which is what made the match notable. Researchers concluded with moderate confidence that Ransom Busters is a single ransomware affiliate working across several ransomware-as-a-service operations rather than an independent party, using its affiliate position to pull ransom negotiations away from the criminal enterprise it works for. The arrangement damages that enterprise, since affiliates in these operations rarely control every copy of stolen data, and a victim paying two parties has no better assurance that either destroyed anything.
What was said
The activity may represent an affiliate attempting "to monetize victims outside the traditional RaaS payment structure," researchers wrote in findings published August 18, 2026. They pointed out that a party claiming to have compromised the administrative panels of criminal groups is describing conduct that could violate the Computer Fraud and Abuse Act, and that no legitimate organization would be expected to commit a crime and charge a fee for doing so. No case has been identified where the approach succeeded.
In the know
The two named ransomware operations most active against healthcare give this context. DragonForce began as a conventional ransomware-as-a-service scheme in August 2023 before rebranding as a cartel and moving to a distributed model that lets affiliates build their own brands under its infrastructure, The Record reported. Anubis runs a tiered structure paying affiliates 80% for traditional encryption attacks, 60% for data extortion, and 50% for selling access alone, an arrangement that draws in criminals with different capabilities. Anubis also built regulatory pressure into its extortion model, threatening to report organizations that refuse payment to data protection authorities, including the Department of Health and Human Services, according to CyberSecurityNews. Its affiliate rules exclude education, government, and non-profit targets while leaving healthcare organizations available.
The big picture
An organization in the first days of a ransomware incident is fielding contact from insurers, counsel, forensic firms, law enforcement, vendors, and press, which is the environment this technique is built for. The identifying signals reported by responders are practical enough to write into a playbook. Legitimate incident response firms make contact after an attack becomes public rather than before, correspond from a verifiable corporate domain rather than a privacy-focused free email service, conduct a scoping call before quoting any price, and never request payment in cryptocurrency. Healthcare organizations should decide now who is authorized to receive and respond to outside contact during an incident, and route everything else to counsel without engagement. Social engineering directed at a team already under pressure works on the same principle as any other lure, with the difference that the target here is the response effort rather than an employee's inbox.
FAQs
Can a victim verify that stolen data has actually been deleted?
No. Deletion cannot be demonstrated, only asserted, and in affiliate-based operations the data may sit with the affiliate, the core group, and anyone either shared it with. Organizations treat data as permanently compromised once exfiltration is confirmed, regardless of what any party promises.
Who should an organization contact when it receives an unexpected offer of help during an incident?
Incident response counsel first, who can assess the communication and decide whether law enforcement should see it. Responders should preserve the message and headers rather than replying, since any engagement gives the sender information about the organization's position.
Why would a criminal undermine the operation they work for?
Affiliates keep a percentage of ransoms rather than the whole amount, so a separate payment collected outside the platform is retained entirely. The tactic works against the operation's long-term credibility, which suggests short-term extraction rather than a coordinated strategy.
Does paying a party claiming to hold your data create legal exposure?
Payments to sanctioned individuals or groups may violate Treasury sanctions regardless of whether the payer knew the recipient's identity, and a party whose only claim is unauthorized access to criminal infrastructure offers no way to establish who is being paid.
What should an incident response plan say about external communications?
It should name who is authorized to speak for the organization, specify that all unsolicited contact routes to counsel, and set an expectation that no financial commitment is made without insurer and legal sign-off. Deciding this in advance removes the pressure to judge an unfamiliar approach while systems are down.
