A Second Extortion Hiding Inside the First
Ransomware victims already face an impossible choice: pay a criminal group or risk having stolen data leaked. Now, according to researchers at GuidePoint Security, some victims are facing a third option they never asked for. An outfit calling itself "Ransom Busters" has been reaching out to companies that have just been hit by ransomware, before the attack becomes public knowledge, and offering to recover encrypted files and delete stolen data for a fraction of the original demand.
On paper, that pitch sounds like a lifeline. In practice, GuidePoint's findings suggest it is a con built on top of a crime that is already devastating. Whoever is behind Ransom Busters appears to know the victim has already been breached, which strongly implies a connection to the ransomware operation itself, or at least privileged access to its victim list. That timing is the whole scam: it works because the target is scared, confused, and desperate for any way out that costs less than the attacker's original ask.
How the Scheme Exploits the Chaos of an Attack
Ransomware negotiations are already murky. Victims rarely know for certain who they are dealing with, whether stolen files were actually deleted after payment, or whether paying invites a repeat attack. That uncertainty is precisely the soil Ransom Busters is planting itself in. By posing as an independent recovery firm rather than the extortionist, the scheme gives victims a false sense that they are dealing with a neutral third party rather than negotiating with criminals directly.
This isn't the first time researchers have flagged this specific group. Earlier reporting on the Ransom Busters scam preying on ransomware victims and a separate writeup on the fake Ransom Busters group scamming ransomware victims both described the same pattern: contact made before public disclosure, a reduced price tag, and promises of data deletion that cannot realistically be verified. GuidePoint's latest research reinforces that this isn't a one-off phishing attempt but an ongoing, apparently profitable racket riding on the back of legitimate ransomware attacks.
The uncomfortable irony is that this scam only works because paying ransomware demands has become normalized enough that a victim will consider a second, unsolicited payment request as plausible. Research from Proofpoint has already shown that 1 in 3 ransomware payers get hit again, meaning organizations that pay once are already statistically more likely to be targeted a second time. Ransom Busters appears to be capitalizing on that same cycle, just from a different angle.
Why This Matters Beyond the Ransom Note
The privacy stakes here go beyond a wasted payment. Victims dealing with Ransom Busters are, by definition, organizations that have already had sensitive data stolen. Every extra communication channel a victim opens, especially one initiated by an unverified party claiming insider knowledge of the breach, is another opportunity for that data to be mishandled, further exposed, or used as leverage. If a victim pays Ransom Busters believing their stolen files will be deleted, they have no real assurance that anything was deleted at all. The data could still be sold, leaked, or held for future extortion.
This fits into a broader pattern documented in coverage of why the ransomware extortion economy persists into 2026: as long as paying remains common and verification remains nearly impossible, criminals will keep finding new ways to insert themselves into the payment process. Ransom Busters is simply the latest variation, exploiting the same trust gap that makes ransomware profitable in the first place.
What This Means For You
If your organization is hit by ransomware, treat any unsolicited offer of recovery help with the same skepticism you would apply to the ransom demand itself. Legitimate incident response firms are engaged by you, not the other way around, and they don't typically reach out proactively before an attack has even become public. A message claiming insider access to your breach details, arriving suspiciously fast, is a major red flag rather than a shortcut.
Organizations should route any ransomware incident through a known, vetted incident response provider or law enforcement contact rather than engaging directly with anyone who approaches them first. Verifying identity, documenting all communications, and resisting the pressure to act quickly are the best defenses against a scam designed to exploit panic.
Key Takeaways
- Be wary of anyone offering ransomware "recovery" services who contacts you before your breach is public.
- Never assume a reduced payment guarantees data deletion; there is no reliable way to verify that promise.
- Work only with incident response firms you or your legal counsel have independently vetted.
- Report suspicious recovery offers to law enforcement, since they may point to insider knowledge of the original attack.
- Understand that paying any party in a ransomware incident, original attacker or otherwise, carries risk and does not guarantee your data's safety.




