A suspected ransomware affiliate is allegedly masquerading as a recovery service called “Ransom Busters,” contacting ransomware victims before incidents become public and offering to help them for a separate fee, according to BleepingComputer. The report cites GuidePoint Security's Research and Intelligence Team, or GRIT, which disclosed the activity after responding to several recent ransomware incidents. The timing of the outreach was central to the concern: victims received emails from Ransom Busters before their attacks had been publicly disclosed, suggesting the sender had some non-public visibility into the intrusions. Ransom Busters claimed it had exploited vulnerabilities in administrative panels used by ransomware-as-a-service operations, according to BleepingComputer. On that basis, the group said it could provide decryption keys and delete stolen data from ransomware servers, including servers associated with DragonForce, Settra, and Anubis. The reported price range for deleting the data was $20,000 to $60,000. GRIT’s assessment is more specific — and still hedged. Based on evidence from two incidents, the researchers believe Ransom Busters is likely not a legitimate recovery firm but the ransomware affiliate responsible for the attacks. BleepingComputer reports that GRIT reached this conclusion after seeing repeated technical overlaps across incidents. Those overlaps included use of the same software tools: SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. GRIT also observed the same tactics, including creation of a local backdoor account using the password “Numlock!123” and the same attacker-controlled hostname, “DESKTOP-BBETH6K.” The team said it saw overlapping activity across multiple ransomware-as-a-service operations and assessed with moderate confidence that Ransom Busters is a single affiliate using its access to divert ransom payments away from the ransomware gangs it works with. BleepingComputer reports that GRIT has not seen any victims pay Ransom Busters and discourages doing so. In one incident involving Ransom Busters, the victim instead paid the ransomware operation behind the attack; researchers said the victim’s name and stolen data were not published on that operation’s leak site, and they found no evidence that Ransom Busters leaked the stolen data outside the ransomware-as-a-service environment. Coveware, a ransomware negotiation firm, separately confirmed to BleepingComputer that it recently responded to at least one incident in which the same group or individual contacted a victim by email and claimed access to both the decryption key and stolen data. Coveware said it has seen similar “middlemen” using other names as far back as 2024, but characterized this case as distinct from typical post-disclosure solicitation because the contact occurred during a non-public incident. The operational risk is straightforward: if a rogue party has access to stolen data or keys, a victim may be negotiating with only one of several actors who can influence the outcome. Coveware told BleepingComputer that this kind of interference increases risk because paying the ransomware operation may no longer ensure that every party with access to the data will honor an agreement not to leak it. Who benefits: Incident-response teams and ransomware negotiators benefit from treating unsolicited “recovery” offers during non-public incidents as potential evidence of attacker access. Defenders also gain actionable indicators from the reported tooling, password, and hostname overlaps. Who's exposed: Ransomware victims are exposed if they assume the party operating a leak site is the only actor with access to their data or decryption material. Ransomware-as-a-service operators are also exposed if affiliates can use campaign access to siphon payments from them.