Threat Intelligence

New Scam Alert: 'Ransom Busters' Preys on Ransomware Victims with Fake Recovery Offers

The Hacker News · 19 Aug 2026
Key Takeaway If you've been hit by ransomware, never respond to unsolicited emails offering to 'delete' your stolen data for a fee—verify any recovery help through trusted, independent security professionals or the ACSC.

Security researchers have identified a new twist on ransomware extortion. A group calling itself Ransom Busters is proactively emailing organisations that have already been hit by ransomware attacks, claiming they can hack into the criminals' servers and delete the victim's stolen data. In exchange, they're demanding payments ranging from $20,000 to $60,000.

According to researchers at GuidePoint, this behaviour is unusual and immediately raised red flags. Legitimate cybersecurity help doesn't typically arrive as an unsolicited email from a third party offering to 'fix' a ransomware incident for a fee. It's likely this is either a scam designed to extract further payment from already-distressed victims, or possibly a ransomware affiliate attempting to profit twice from the same attack—once from the original ransom demand, and again by posing as a rescuer.

For Australian small businesses, this highlights a growing trend: cybercriminals are finding creative ways to exploit victims even after an initial attack has occurred. Anyone who has suffered a ransomware incident should be especially wary of unsolicited offers of help, no matter how convincing they sound, and should verify any communication through trusted, independent cybersecurity professionals or law enforcement rather than engaging directly with the sender.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.