discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.

By Ravie Lakshmanan·Aug 18·thehackernews.com·3 min read

Intelligence analysis by Llama

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
Image: thehackernews.com

Ransom Busters, a ransomware affiliate, is claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. This is an anomalous behavior as cybersecurity firms commonly reach out to ransomware victims after the attack becomes public knowledge.

Why it matters

This story matters as it highlights the evolving tactics of ransomware affiliates, who are now proactively contacting victims and claiming to delete stolen data in exchange for a fee. This development has significant implications for ransomware victims and the cybersecurity industry as a whole.

Imagine you're a company that's been hacked by ransomware. A group called Ransom Busters contacts you, saying they can help you get your data back if you pay them between $20,000 and $60,000. But this is a trick - Ransom Busters is actually a group of hackers who are trying to scam you. They're not really helping you, and they're just trying to make money off of you.

Analysis

Ransom Busters' Claims: A New Twist in Ransomware Tactics

Ransom Busters, a ransomware affiliate, has been spotted proactively sending emails to victim organizations, claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. This behavior is anomalous as cybersecurity firms commonly reach out to ransomware victims after the attack becomes public knowledge.

GuidePoint Research and Intelligence Team (GRIT) has observed this modus operandi in several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations. The financially motivated threat actor claims to have found vulnerabilities in administrative panels maintained by RaaS groups and broken into the servers for over three years.

The cybersecurity company has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple RaaS operations. In emails sent to the victims, Ransom Busters is seen requesting contact with their CEO or IT leadership, while claiming to have found data stolen from the company on one of the servers they recently accessed and asks them to make a payment that's anywhere between $20,000 and $60,000 to help them regain access to their files and data and delete all backups held by the ransomware group.

GuidePoint said it observed the modus operandi when responding to incidents from threat groups including DragonForce, Settra, and Anubis, adding that the possibility that it could be the work of a legitimate organization is extremely unlikely, as it amounts to a violation of the U.S. Computer Fraud Abuse Act.

UNC6671's Extortion Attacks

The disclosure comes as GuidePoint sheds light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 (aka Cordial Spider and O-UNC-045) targeting financial services, legal, and other industries since April under various extortion brands, such as Falcon, Helix, Pink, Redact, and BlackFile.

The observed behavior, which mirrors similar SaaS-centric targeting from groups such as Shiny Hunters, reflects a departure from opportunistic ransomware deployment and data extortion towards purposeful targeting of large victim organizations, also known as 'big game hunting.'

More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the time period. The average extortion amount stood at $600,000. As many as 78 unique victim-targeted phishing sub-domains have been identified across 76 distinct organizations spanning 15 industry sectors. Of these, 40% are related to hedge funds, venture capital, private equity, asset management, and other financial services firms.

Implications for Ransomware Victims

The developments dovetail with the continued evolution of the ransomware landscape, with the emergence of new groups like Tengu , CRPx0 , Maj

Key points

  • Ransom Busters, a ransomware affiliate, is claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
  • This behavior is anomalous as cybersecurity firms commonly reach out to ransomware victims after the attack becomes public knowledge.
  • GuidePoint has observed this modus operandi in several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple RaaS operations.
  • The financially motivated threat actor claims to have found vulnerabilities in administrative panels maintained by RaaS groups and broken into the servers for over three years.
  • GuidePoint has shed light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 targeting financial services, legal, and other industries since April under various extortion brands.
The Upside

If Ransom Busters' claims are genuine, it could lead to a decrease in ransomware attacks as victims may be more willing to pay for legitimate help rather than succumbing to extortion. However, the likelihood of this being a legitimate operation is extremely low, and the majority of ransomware victims should remain cautious and not fall for such scams.

The Downside

The emergence of Ransom Busters and their claims to delete stolen data in exchange for a fee could lead to a new wave of ransomware attacks, as victims may be more willing to pay for what they believe is legitimate help. This could also lead to a decrease in trust between victims and cybersecurity firms, as some may view these claims as a legitimate offer rather than a scam.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscybercrimeransomwaresecurityhackingextortion

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Aug 18, 2026

Source

thehackernews.com

Share

Topics

cybercrimeransomwaresecurityhackingextortion

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.