What is Ransom Busters?
GuidePoint's Research and Intelligence Team (GRIT) responded to several ransomware incidents in which the victim received an unexpected email from "Ransom Busters LTD" addressed to the CEO or IT leadership. The pitch: it had spent years infiltrating criminal servers, had found the victim's stolen data, and could return the files and destroy every copy the attackers held for $20,000 to $60,000.
One detail gave it away. The emails arrived before the incidents were public, and legitimate firms learn about attacks from disclosure. A rescuer with earlier knowledge got it from somewhere.
How did GuidePoint tie the rescuer to the attacker?
Forensics. Across two incidents in which Ransom Busters made contact, GRIT found the same network scanner, the same exfiltration utility, identical remote management software, one shared backdoor password, and one shared attacker hostname. Its assessment, at moderate confidence: Ransom Busters is a ransomware affiliate working across DragonForce, Settra, and Anubis operations, extorting victims it already helped attack. When questioned, the actor confirmed it held the exact dataset the original attacker had stolen. GuidePoint told BleepingComputer it has seen no victim pay.
Murky rescuers have been a longstanding feature of this market. ProPublica caught "data recovery" firms paying ransoms behind clients' backs back in 2019. The new part is the source: an insider opening a competing negotiation before the first one starts.
Why does a fake rescue work on ransomware victims?
Because the attack puts victims exactly where a fake rescuer wants them. Modern ransomware pairs encryption with data theft, and a restore can undo encryption, but nothing can undo a leak. So a stranger promising deletion for $20,000, a fraction of a typical demand, sounds like a bargain. A discount ransom is still a ransom, paid to someone with every incentive to keep a copy.
The numbers say victims already trust the wrong things. In Eon's 2026 survey of 583 cloud IT leaders, 90% said they were confident they could recover from a cyberattack. Within that confident group, 80% had a recovery failure in the prior year. And 77% worry that their recovery environments themselves could be targeted, for good reason: once your copies are gone or suspect, the attacker's copy is the only copy, at whatever price the attacker names. An attacker posing as a rescuer walks straight through that gap.
What does a restore you can actually trust look like?
The lesson is bigger than one scam. After an incident, a victim can verify almost nothing: the decryptor, the deletion promise, even the cleanliness of their remaining snapshots are all outside their control. You build trustworthy recovery before the attack, and it rests on two properties.
Separation. Geographic redundancy is not security isolation. A copy in a second region still falls to the same stolen credentials. Recovery copies belong in a separate trust domain: a different cloud organization or account, with credentials that share nothing with production.
Verification. A safe copy and a clean copy answer different questions. The Ransom Busters intrusions had backdoor accounts, remote tools, and staged exfiltration in place ahead of the ransom note, and snapshots from that window carry the intruder. Restoring without a tampering check can restore the attacker too.
Get both right and the pitch loses its market. A victim who can restore verified-clean data from an account the attacker never touched has no reason to buy anything from a stranger, whatever the discount.
Where Eon fits
We built Eon Data Protection for exactly this trust problem, starting with where recovery copies live. Protected data lands in immutable, logically air-gapped vaults in a separate account from production, connected via a single read-only IAM role with no agents or appliances in your environment. Stolen production credentials stop at the vault boundary, so the scenario that feeds Ransom Busters (your copies gone and their copy for sale) never forms.
The second half is proving the copy is clean. Before you restore anything, Eon confirms no ransomware rode into the recovery point itself. It scans for encryption, deletion, and tampering across VMs, object storage, and managed databases. For databases, it reads the logical content of each snapshot (row counts, column values, cardinality, schema structure), the only approach that works where no files exist to scan. Eon marks the last clean recovery point, so the restore starts from a copy you've proven.
Clean matters most when you can act on it fast. Eon restores in minutes at whatever grain the damage calls for: a full environment, a single table, or the exact records an attacker or rogue agent touched.
If your recovery plan still assumes the attacker never reaches the vault, our guide to building a ransomware DR plan for the cloud covers account structure, credential separation, clean-point testing, and restore drills.
FAQ
Is Ransom Busters a legitimate recovery service?
Probably not. GuidePoint assesses with moderate confidence that it is a ransomware affiliate running a second round of extortion, and the actor held the same stolen dataset as the original attacker.
Should a victim ever pay a third party to delete stolen data?
Deletion is unverifiable. Researchers have documented criminals keeping copies of stolen data for resale or later re-extortion after payment. Payment to any party, original attacker or self-declared rescuer, buys a promise nobody can check.
How is this different from hiring an incident response firm or negotiator?
Reputable incident response firms and law enforcement engage at the victim's request, and they never claim to hold your stolen data. An unsolicited offer that arrives before your breach is public, from someone holding your data, is extortion with better manners.
How do you know a recovery point is clean?
You check it before you restore. Detection has to look inside the data itself: row-count anomalies and schema changes in databases, mass deletions in object storage, entropy shifts in VMs. Our ransomware attack response plan guide covers clean-point recovery in detail.
What should you do if Ransom Busters contacts your company?
Report the outreach to your incident response team and law enforcement immediately, per GuidePoint's guidance. Treat the contact itself as evidence, since it likely means the sender participated in the intrusion.




