The “Rescue” Was Another Ransom... Inside Ransom Busters
GuidePoint says a supposed ransomware-recovery service contacted victims before some incidents were public. Accurate details can prove access without proving that the person offering help is trustworthy.
Incident overview
GuidePoint Security reported several ransomware incidents in which victims received unsolicited recovery offers from a group calling itself Ransom Busters. GuidePoint assesses with moderate confidence that the persona is a ransomware affiliate using an alternate extortion approach.
Why it works
An organization already facing stolen data and disrupted systems is choosing inside an existing loss. A risky promise that everything can still be undone may feel more attractive because it preserves a possible path back to zero.
Protective actions
- Decide before an incident who is allowed to communicate with attackers or unexpected recovery services.
- Route unsolicited recovery offers to the designated incident-response lead instead of replying through the channel that introduced the offer.
- Ask legal counsel, the cyber insurer, a known response provider, or law enforcement to verify claims independently.
- Do not treat accurate nonpublic details as proof that the person using them is an independent rescuer.
- Assume that promises to delete every stolen copy cannot be independently guaranteed.
Video companion
Watch the breakdown
The recovery offer arrived before the story was public
On August 18, 2026, GuidePoint Security’s Research and Intelligence Team described several ransomware incidents in which victims received unexpected emails from a group calling itself Ransom Busters.
The messages claimed the group had gained access to ransomware infrastructure, found the victim’s data, obtained encryption keys, and could return files while deleting the stolen copies. The requested fee ranged from $20,000 to $60,000.
Some organizations were contacted before their incidents were public. That timing gave the sender access to accurate information that an ordinary outsider would not be expected to know.
Accurate details can demonstrate access. They do not establish whether the person using those details is an independent rescuer.
What GuidePoint found
GuidePoint compared two incidents and reported several unusually specific similarities, including reconnaissance tooling, an attacker-controlled hostname, and the password used to create a backdoor account.
Based on those findings, GuidePoint assesses with moderate confidence that Ransom Busters is a ransomware affiliate working across several ransomware-as-a-service operations and trying an alternate form of extortion. That is a sourced assessment, not a proven identity for every person or criminal group involved.
The affected organizations were not named. GuidePoint did not report whether any victim paid the group. The public evidence also cannot establish that Ransom Busters could return every file or delete every stolen copy.
The stolen-car test
Imagine someone steals your car. Before you report it or tell anyone, a stranger approaches while you are still looking at the empty parking space.
They know the license plate and what was sitting in the back seat. Then they say they broke into the thief’s garage and can return the car for a smaller fee.
Those details make access plausible. They also make the source of that access the most important question. Knowledge of the car does not prove that the stranger is there to rescue you.
The psychology: prospect theory
Prospect theory describes how people evaluate possible outcomes relative to a reference point. One of its best-known patterns is that a risky option can become more attractive when a choice is framed around losses.
In a hypothetical problem reported by Daniel Kahneman and Amos Tversky in 1979, 95 participants chose between a certain loss of 3,000 and an 80% chance of losing 4,000 with a 20% chance of losing nothing. Ninety-two percent chose the gamble.
The study did not involve ransomware, organizations, or real money lost during an incident. It does not show that a ransomware victim will respond in any particular way. It demonstrates a narrower pattern: when a loss already feels unavoidable, a gamble that preserves some chance of escaping the loss can feel unusually attractive.
For a ransomware victim, the stolen data and disruption are the existing loss. The supposed recovery service offers a risky possibility that everything can still be undone.
Fact, interpretation, and uncertainty
The messages, requested payment range, incident timing, technical similarities, and moderate-confidence affiliate assessment are GuidePoint’s findings.
The prospect-theory connection is Connor’s cyberpsychology interpretation. It does not diagnose the affected organizations, establish their internal decision-making, or suggest that victims are irrational.
Whether Ransom Busters can recover anything, whether victims paid, and whether the ransomware operations knowingly participated in the rescue persona remain unconfirmed in the public reporting.
Decide who verifies the rescue before the crisis
The practical answer is not to improvise a better decision while systems are down and pressure is high. Decide in advance:
- Who is allowed to communicate with attackers.
- Who can evaluate a recovery claim.
- Which legal counsel, insurer, response provider, and law-enforcement contacts will be involved.
- Where an unexpected offer must be routed without engaging the sender.
Do not let an incoming recovery offer establish the channel through which it is verified.
A small ransom is still a ransom, even when it is wrapped up like a miracle way out.
Full spoken transcript
Some ransomware victims are getting a second ransom demand disguised as a rescue from the first one.
GuidePoint Security says it's responded to several recent ransomware incidents where the victims received an unexpected email from a group calling itself Ransom Busters.
According to the message, Ransom Busters claimed to have returned the files and deleted every backup the ransomware group had made, all for the low, low price of twenty thousand to sixty thousand US dollars.
If the name Ransom Busters, or the fact that there’s no reliable way to verify every stolen copy was deleted isn’t enough to make you suspicious, there’s more.
Some of the companies being contacted hadn’t made the initial attack public yet. So the victims are being contacted before anyone outside the incident response team even knew what happened.
So imagine you’re running one of these companies. Your systems are down, your data’s been stolen, and everyone’s waiting for answers as to what happened.
Then a stranger shows up with accurate information that only someone connected with the attack would know, and offers to fix it all if you pay them. It’s basically just the same attack with a slightly different paint job.
It’s like if someone steals your car, and before you report it as stolen or tell anyone about it, a stranger shows up while you’re still standing in the parking lot looking at where your car was and says they broke into the thief’s garage.
They know your license plate number, and they know what you had sitting in the back seat. And they say they can return your car if you pay them a small fee.
Now, the fact that they know these details strongly suggests that they do have access to your car, but it shouldn’t prove that they’re your rescuer in this situation. It should make you wonder why they knew what your car was in the first place.
If the context alone wasn’t enough to suggest that the initial attack and Ransom Busters were connected, GuidePoint found some other similarities. The same reconnaissance tools were used across both incidents, the same attacker-controlled computer name was used, and the exact same unusually specific password was used when creating a backdoor account.
In short, the situation looks like criminals undercutting other criminals they’re working with and trying to call it customer service. There was never a guarantee your stolen data would be deleted if you pay, and you should have a healthy skepticism of your friendly neighborhood Good Samaritan.
That desperate moment where you think, maybe this can fix everything, connects really well to prospect theory. Similar to loss aversion, it reveals our willingness to gamble can change once we’re already facing a loss.
When we’re choosing between possible gains, we’re usually fairly cautious.
But once we’re already losing, a risky option can become more attractive because it keeps the hope alive that we can escape the loss completely.
In a 1979 experiment, ninety-five people were given a hypothetical choice. They could accept a guaranteed loss of three thousand dollars, or they could take an eighty percent chance of losing four thousand dollars with a twenty percent chance of losing nothing.
Ninety-two percent chose to gamble. And it does sound pretty good, right? You’re already facing a loss of three thousand dollars, and here’s this opportunity to lose nothing, even if you’re risking a high chance of a larger loss.
Now, choosing between two losses and making a hypothetical gamble in a study isn’t quite the same thing as running an organization during a ransomware attack. Real ransomware decisions involve employees, customers, legal obligations, insurance, and potentially millions of dollars. So there are a lot more variables on the table.
But the lesson here is still useful. Being in the middle of a loss can change what feels reasonable. The people that make the offer don’t necessarily need to feel trustworthy. They just have to offer something that feels like the last remaining path back to zero.
So the practical takeaway here isn’t that ransomware victims are irrational or that leaders need to find ways to improvise better decisions when the heat is on. It’s that you need to decide before the crisis: who’s allowed to communicate with the attackers and who verifies the recovery claims.
If an unexpected offer shows up, it should go directly to your incident response lead, legal counsel, or to law enforcement.
There should be a clear playbook on how these situations get handled.
The offer may be enticing. But there’s no guarantee of anything positive.
A small ransom is still a ransom, even when it’s wrapped up like a miracle way out.
So as always, stay mindful, stay resilient. Remember, sometimes a bad gamble can look good in the wrong light. And follow for more cyberpsychology breakdowns.
Sources
- Beware Ransom Busters (opens in a new tab)
GuidePoint Security Research and Intelligence Team · August 18, 2026
Supports: Primary investigation for the unsolicited recovery messages, contact before some incidents were public, claimed access, requested payments, similarities observed across two investigated incidents, and GuidePoint’s moderate-confidence ransomware-affiliate assessment.
- Prospect Theory: An Analysis of Decision under Risk (opens in a new tab)
Econometrica
Supports: Primary psychology paper for the risk-seeking pattern in a hypothetical choice between a certain loss and a gamble that included a chance of no loss. It did not study ransomware, scams, or organizational response.
- #StopRansomware Guide (opens in a new tab)
Cybersecurity and Infrastructure Security Agency · October 19, 2023
Supports: Authoritative preparation and response guidance supporting a planned, coordinated incident-response process and engagement with law enforcement.
Related cases
Video breakdownThe Medical Scam That Knows Your Real Information
Madera Community Hospital’s notice shows how accurate personal and health details can make a false approach feel pre-verified. The safer habit is to verify healthcare requests through a separate channel you control.
