← Back to Feed
Rogue ransomware affiliate poses as recovery firm to steal payments
August 19, 2026 · BleepingComputer · Severity: CRITICAL
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.
Key Takeaways
- A suspected ransomware affiliate is posing as a legitimate ransomware recovery service called Ransom Busters to scam victims.
- The attackers contact victims before attacks become public, offering decryption services for a fee while being connected to the ransomware operation itself.
- Organizations should verify the legitimacy of any ransomware recovery service through independent security channels before engaging.