In a new twist in the world of cyber threats, ransomware victims are now contending with deceptive tactics from scammers posing as recovery firms. These fraudulent entities, such as the self-proclaimed ‘Ransom Busters,’ contact victims with offers to recover their data and erase stolen copies for a substantial fee.
The Rise of Ransom Busters
Pretending to be a legitimate data recovery service, Ransom Busters reaches out to companies before their data breaches become public knowledge. Their approach, targeting high-level executives or IT leaders, raises suspicions about how they obtain such sensitive information. This method, as assessed by investigators, reveals their operations as a clever guise by ransomware affiliates.
According to GuidePoint Security, a detailed report shared with Cyber Security News highlights that this scam was identified during investigations into incidents linked to groups like DragonForce, Settra, and Anubis. The presence of such scams complicates the aftermath of ransomware attacks, where organizations are already struggling to manage damage, gather evidence, and determine trustworthy allies.
Deceptive Tactics and Legal Implications
Ransom Busters claims to have breached criminal servers, accessing encryption keys and stolen data. They present themselves as saviors, yet demand payments between $20,000 and $60,000 to supposedly delete compromised information. However, their access to data held by ransomware affiliates questions their independence.
These actions not only present ethical dilemmas but also potential legal issues. Accessing another group’s servers without authorization, even those operated by criminals, could violate the Computer Fraud and Abuse Act. Genuine recovery services do not require payments for such operations, highlighting the dubious nature of these claims.
Investigative Findings and Recommendations
GuidePoint’s incident-response team reviewed cases involving Ransom Busters and observed common tools used for network mapping, data exfiltration, and remote management. Despite the variety of available tools, the consistent use across incidents suggested a single affiliate might be behind Ransom Busters’ operations.
Victims are advised to treat unsolicited recovery offers with caution. They should communicate with their incident-response teams and law enforcement, verifying claims independently. Paying these imposters offers no assurance that stolen data will be recovered or erased.
Conclusion: Vigilance is Key
The central message is clear: criminals posing as rescuers remain extortionists. True recovery requires thorough investigation and not falling into the trap of a second ransom demand. Organizations must remain vigilant and seek help from trusted cybersecurity experts to navigate these threats efficiently.
