GuidePoint's threat intel team says the 'recovery firm' emailing breached companies with a $60,000 fix is running the same infrastructure as the original attack.
If a ransomware gang already stole your files this year, brace yourself — there's a second group now emailing victims pretending to be the good guys. GuidePoint's threat intel team, GRIT, is calling it Ransom Busters, and it isn't a recovery firm at all. It's very likely the same criminals asking to get paid twice: once to encrypt you, once more to "find" the leverage they already had the entire time.
How the scam actually works
The pitch arrives cold, usually by email, and it's specific enough to feel credible. Ransom Busters claims to have quietly breached the administrative panels of major ransomware-as-a-service operations and has been sitting on that access for "over three years." It says it found your company's stolen data sitting on those servers. It offers to delete the backups and hand back your files — for a fee between $20,000 and $60,000, paid directly to them, no negotiation with the original attackers required. It asks, specifically, to be put in touch with your CEO or IT leadership rather than a security team, which tells you exactly who it's trying to pressure.
An email lands at a company that's already been through a ransomware breach.
It claims to have hacked into the ransomware gang's own infrastructure.
It says it can locate and delete your specific stolen data.
It demands $20,000–$60,000, payable to them, not the original attacker.
It asks to speak directly with your CEO or IT leadership, not your security desk.
Who's actually behind Ransom Busters
GuidePoint's GRIT team, led by principal consultant Justin Timothy, connected two separate victim incidents using identical forensic fingerprints: the same SoftPerfect Network Scanner build, the same s5cmd tool used to pull data out to AWS storage, the same remote-monitoring software installed for persistence, a backdoor account with the password "Numlock!123," and an attacker workstation identified by the exact same hostname — DESKTOP-BBETH6K — across incidents. That's not coincidence-level overlap. It's the signature of one operator running both the original intrusion and the follow-up "recovery" pitch.
$20K–$60K
Demanded
per victim, on top of any ransom already paid
3+ years
Claimed access window
an unverified claim inside the extortion email
3
Ransomware brands linked
DragonForce, Settra, and Anubis incidents
4
Shared forensic artifacts
same scanner, exfil tool, backdoor account, and hostname across incidents
GuidePoint's investigators say the 'recovery' pitch traces back to infrastructure already tied to the original intrusion — not an outside rescuer. · Unsplash
This isn't new — it's an old grift with better branding
Fake recovery scams targeting individual ransomware victims aren't a new idea; smaller operators have run "we'll negotiate your ransom down" schemes for years. What's different here is scale and confidence — this reads like a deliberate second product line bolted onto an existing ransomware operation, aimed specifically at victims who are already scared, already burned once, and already primed to believe someone can make the pain stop for a price. That's a genuinely nastier evolution of double extortion, and I'd expect other affiliates to copy it once they see it works.
What to do if you get one of these emails
Don't reply from the address it arrived at — verify independently through your incident-response provider first.
Treat any 'proof' screenshot as unverified; it may be recycled from a public leak-site post.
Loop in legal counsel and your cyber-insurance carrier before any contact happens.
Never wire funds on a promise to delete stolen data — no confirmed case of that promise being kept has surfaced.
Report it to law enforcement (FBI IC3 in the US, or your national equivalent) — this is extortion, not a service.
Is Ransom Busters a real data-recovery service?
No. GuidePoint's investigators found it shares infrastructure and tooling with the ransomware intrusions it claims to be fixing.
Which ransomware groups' victims are being targeted?
Incidents tied to DragonForce, Settra, and Anubis attacks, according to GuidePoint's GRIT team.
Should I pay if I already paid the original ransom?
There's no good reason to. Researchers found no confirmed case of a criminal group actually deleting exfiltrated data after a second payment.
How can I tell if a recovery-service email like this is legitimate?
Genuine incident-response firms don't cold-email your CEO demanding a specific dollar figure on a deadline. Verify independently before engaging anyone claiming this role.