← Back to Feed

Rogue ransomware affiliate poses as recovery firm to steal payments

August 19, 2026 · BleepingComputer · Severity: CRITICAL

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.

Key Takeaways

  • A suspected ransomware affiliate is posing as a legitimate ransomware recovery service called Ransom Busters to scam victims.
  • The attackers contact victims before attacks become public, offering decryption services for a fee while being connected to the ransomware operation itself.
  • Organizations should verify the legitimacy of any ransomware recovery service through independent security channels before engaging.
☕ Buy a Coffee