By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Ransom Busters Offers Data Deletion for Up to $60,000

A newly identified entity operating under the name Ransom Busters has begun contacting organizations that have been victims of ransomware attacks, offering a novel service: the deletion of stolen data directly from the servers of the ransomware groups themselves. This operation, detailed in a report by GuidePoint Security, involves sending unsolicited emails to victim companies, proposing to act as an intermediary to remove sensitive information that was exfiltrated during the initial breach. The fees demanded by Ransom Busters for this service range significantly, from a minimum of $20,000 to a maximum of $60,000 per incident. This approach marks a departure from typical ransomware response services, which often focus on decryption, negotiation with attackers, or forensic analysis. The unusual nature of Ransom Busters' offer, as highlighted by GuidePoint Research, immediately flags it as anomalous within the cybersecurity landscape. Typically, victims are advised to engage with incident response professionals or law enforcement, rather than a third party claiming to directly manipulate the infrastructure of cybercriminals. The modus operandi of Ransom Busters suggests a potential exploitation of the desperation and fear experienced by victims who have had their data stolen, a common tactic employed by various actors in the cybercrime ecosystem. The specific methods by which Ransom Busters claims to access and delete data from ransomware servers remain unclear, raising significant questions about the legitimacy and feasibility of their claims. It is possible that they are either posing as a legitimate service to extort money from victims or are themselves involved in illicit activities, perhaps by having gained access to the same or similar data through other means. The cybersecurity community is advised to exercise extreme caution when encountering such unsolicited offers, as they could represent a new form of social engineering or a sophisticated scam designed to capitalize on the aftermath of a cyberattack. The involvement of ransomware groups in data exfiltration has become increasingly prevalent, with many groups now employing a double-extortion strategy, threatening to leak or sell stolen data if ransom demands are not met. This tactic adds another layer of complexity and pressure on victim organizations, making them more vulnerable to deceptive offers. GuidePoint Security's observation that the offer is "anomalous" underscores the need for thorough vetting of any third-party service provider claiming to resolve data breach issues, especially those that operate outside established channels of cybersecurity incident response. The potential for these services to be a scam, or even a front for further malicious activity, is a significant concern for organizations already grappling with the fallout of a ransomware attack. The exact timeline of Ransom Busters' emergence and the full scope of their operations are still under investigation, but their proactive outreach indicates an intent to establish a presence in the post-breach market.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.