A Second Predator Circling the Same Victims

Getting hit by ransomware is bad enough. Now a threat actor calling itself "Ransom Busters" is finding a way to profit from the same victims twice. According to reporting on the scheme, this group approaches organizations that have already suffered a ransomware attack and offers to "delete" their stolen data, for a price ranging from $20,000 to $60,000.

The pitch sounds almost helpful on the surface: pay us, and we'll make sure your stolen files never surface publicly or get sold on. In reality, researchers analyzing the group's tools and infrastructure have found little to suggest that payment guarantees anything at all. The Ransom Busters scam appears to be less a recovery service and more a second extortion attempt layered on top of the first.

How the Ransom Busters Scheme Works

Security analysis of the group's activity points to a pattern that has now been documented across multiple reports: Ransom Busters positions itself as a third party with access to a ransomware gang's servers, claiming it can intervene on the victim's behalf. In some cases, the group appears to be an affiliate operating within the same ransomware ecosystem it claims to be fighting, rather than an outside rescuer.

Researchers examining the tooling behind these approaches identified backdoor markers and infrastructure overlaps that suggest continuity with existing ransomware operations rather than a genuinely independent recovery service. In other words, the people offering to "delete" your stolen data may have had a hand in stealing it in the first place, or at minimum maintain close ties to those who did.

This matters because it changes the calculus for victims entirely. A payment made in good faith to a legitimate incident response firm is one thing. A payment made to an entity that may still control your stolen files, or that has no real ability to guarantee deletion, is another. As covered in reporting on how fake recovery firms hide behind the ransomware scam, there is no verifiable mechanism to confirm that data has actually been destroyed once a ransom-style payment changes hands.

Why Payment Guarantees Nothing

The core problem with any pay-to-delete offer, whether from the original attacker or a supposed third party like Ransom Busters, is verification. Once stolen data leaves an organization's network, the victim has no way to confirm what happens to it next. A screenshot of a deleted folder or a verbal assurance is not proof. Copies can be made before any "deletion" occurs, and there is no independent auditor checking a criminal group's compliance with a payment agreement.

This is a trend security professionals have flagged for years with traditional ransomware payments, and it applies with even more force here. Ransom Busters is essentially asking victims to trust an entity whose entire business model depends on victims already being desperate, having just been through one extortion event and now facing a second demand from a party claiming to offer relief. The warning trend researchers point to is straightforward: the extortion economy is diversifying, with new actors finding ways to monetize victim fear even after the original attack has concluded.

What This Means For You

If your organization has experienced a ransomware incident, and someone contacts you afterward, whether through email, a dark web portal, or a direct message, offering to delete stolen data for a fee, treat that outreach with the same skepticism you'd apply to the original ransom note. There is no reliable way to verify the claim, and paying does not create any enforceable guarantee.

The safest path is to route any such contact through your incident response team or a trusted cybersecurity firm rather than negotiating directly. Law enforcement agencies handling ransomware cases are generally aware of secondary extortion schemes like this one and can help assess whether a specific approach is credible or simply another angle on the same attack.

Actionable Takeaways

  • Do not treat any post-breach "data deletion" offer as legitimate without independent verification from your security or legal team.
  • Report contact from groups like Ransom Busters to law enforcement rather than negotiating unilaterally.
  • Assume that any data already exfiltrated in a ransomware attack should be treated as permanently exposed, regardless of any payment made afterward.
  • Strengthen backup and detection practices now so a first ransomware event, and the follow-on extortion it invites, becomes less likely in the first place.

The rise of schemes like Ransom Busters is a reminder that ransomware's aftermath can be just as dangerous as the initial attack. Staying skeptical of anyone offering a shortcut back to safety, especially for a price, remains the best defense.