A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
August 18, 2026
A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model.
According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as "Ransom Busters" has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters "can return your files to you and destroy all backups held by the group." The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files.
"We observed this behavior while responding to incidents from threat groups including DragonForce, Settra, and Anubis," according to the blog post, released today. "The threat actor claimed this access allowed them control over 'almost all of their infrastructure. Like [ransomware as a service [RaaS] groups, Ransom Busters' motivation appears to be financial. Ransom Busters confirmed access to the exact same dataset that the ransomware affiliate possessed, when questioned. The group offered to delete the victim's stolen data from the ransomware groups' servers for a fee of between $20,000 to $60,000."






