New Scam Alert: 'Ransom Busters' Preys on Ransomware Victims with Fake Recovery Offers
Security researchers have identified a new twist on ransomware extortion. A group calling itself Ransom Busters is proactively emailing organisations that have already been hit by ransomware attacks, claiming they can hack into the criminals' servers and delete the victim's stolen data. In exchange, they're demanding payments ranging from $20,000 to $60,000.
According to researchers at GuidePoint, this behaviour is unusual and immediately raised red flags. Legitimate cybersecurity help doesn't typically arrive as an unsolicited email from a third party offering to 'fix' a ransomware incident for a fee. It's likely this is either a scam designed to extract further payment from already-distressed victims, or possibly a ransomware affiliate attempting to profit twice from the same attack—once from the original ransom demand, and again by posing as a rescuer.
For Australian small businesses, this highlights a growing trend: cybercriminals are finding creative ways to exploit victims even after an initial attack has occurred. Anyone who has suffered a ransomware incident should be especially wary of unsolicited offers of help, no matter how convincing they sound, and should verify any communication through trusted, independent cybersecurity professionals or law enforcement rather than engaging directly with the sender.