Ransomware victims are receiving unsolicited emails from an entity calling itself Ransom Busters LTD, offering to delete stolen data and supply decryption keys for $20,000 to $60,000. The pitch is that the sender has spent years infiltrating ransomware-as-a-service infrastructure and has found vulnerabilities in the administrative panels affiliates use to manage their attacks.

GuidePoint Security’s Research and Intelligence Team (GRIT), which first documented the scheme, reached a different conclusion: Ransom Busters is a single ransomware affiliate stealing payments from the gangs it works for.

The Detail That Gives It Away

The emails arrive before the underlying attacks are publicly known.

Victims reported being contacted by “Ransom Busters LTD” — requesting a conversation with executives or IT leadership — while their incidents were still non-public. No leak-site listing, no press coverage, no regulatory filing. GRIT’s investigators asked the obvious question: how does an outside party learn about an undisclosed intrusion at the exact moment it becomes monetizable?

Then they looked at the attacks themselves. Across multiple incidents where victims later received Ransom Busters emails, GRIT found overlapping intrusion patterns — identical tooling including SoftPerfect Network Scanner, s5cmd and Remotely, and matching credentials reused between cases.

That is not the fingerprint of a researcher who compromised a RaaS panel. That is the fingerprint of the person who ran the intrusions.

Named Brands, One Operator

The Ransom Busters messages claim access to data held by DragonForce, Settra and Anubis — three operations we have tracked separately through 2026, including DragonForce’s cartel expansion and Anubis’s Citrix Bleed 2 campaign.

Affiliates commonly work across multiple RaaS brands. An affiliate with active engagements under DragonForce, Settra and Anubis has legitimate access to exactly the three victim sets Ransom Busters claims to have “discovered” — without needing to compromise anything.

The business logic is straightforward. A RaaS affiliate typically surrenders 20–30% of every ransom to the operator. An affiliate who contacts the victim off-platform, under a different name, before the operator posts the leak-site listing, keeps 100% — and collects it in a window where the victim has not yet spoken to counsel, insurers or an incident response firm.

Why the Offer Is Worthless Even If the Access Is Real

Coveware confirms encountering similar approaches and draws the important distinction: this is materially worse than the “ambulance chasers” who scrape leak sites and cold-call victims with recovery services. Those are opportunists selling a service. This is a party with hands-on access to the stolen data offering to be paid not to use it.

There is no version of this transaction that works for the victim:

  • Deletion is unverifiable. It always is, in every ransomware negotiation. But here the counterparty is not even the entity claiming to hold the data under a brand with a reputation to maintain.
  • The keys may not be genuine. An affiliate who is defrauding the operator may not have clean access to working decryptors.
  • Network access is not addressed. Paying an intermediary does nothing about the persistence mechanisms still in place.
  • The original operator still posts. If the affiliate has gone rogue, the RaaS brand’s leak-site timer runs regardless. Payment to Ransom Busters buys nothing from the party that will actually publish.
  • Payment likely violates the terms of your cyber policy and may complicate sanctions screening that an incident response firm would otherwise run.

Coveware’s framing is the one that matters operationally: interference from a rogue party with access to stolen data increases risk to the victim. It adds an uncontrolled actor to a negotiation that already has too many.

Both GuidePoint and Coveware advise victims not to pay.

What Organizations Should Do

Route unsolicited breach outreach to counsel and IR, not to IT. An email claiming knowledge of your undisclosed incident is itself a piece of incident evidence — it narrows the actor set and establishes a timeline. Preserve it with headers intact.

Treat pre-disclosure contact as confirmation, not speculation. If someone knows about an intrusion you have not announced, they have a source. In this pattern, they are the source.

Do not negotiate through unverified channels. Every legitimate ransomware negotiation runs through the operator’s designated channel, mediated by a firm that does this professionally. Off-platform contact from a new name is a fraud indicator in the criminal economy exactly as it is in the legitimate one.

Hunt for the named tooling. SoftPerfect Network Scanner, s5cmd and Remotely in your environment are worth investigating on their own merits — s5cmd in particular is a strong exfiltration signal, since its purpose is high-speed bulk transfer to S3-compatible storage.

Sources