# The Third Bill: Ransomware Victims Are Now Being Shaken Down by Someone Who Claims to Be on Their Side


When your company's data lands on a ransomware group's leak site, you've already lost something you can't fully recover — time, trust, and often a significant ransom payment. Now a threat actor calling itself Ransom Busters has found a way to make that wound bleed a little longer: by cold-emailing victims and offering to delete their stolen data from the gang's servers for anywhere between $20,000 and $60,000.


The pitch is almost elegant in its cynicism.


## The Scheme


GuidePoint Research flagged the activity after spotting emails that, on the surface, read like victim assistance outreach. Ransom Busters presents itself as a benevolent third party — someone who has penetrated the ransomware group's infrastructure and can, for a fee, purge the exfiltrated data before it gets weaponized further.


The claim is this: we hacked the hackers. Pay us, we delete your files.


What's notable here isn't the audacity — ransomware economics have always attracted opportunists. What's notable is the mechanism. GuidePoint researchers described the outreach as "anomalous" precisely because it inverts the typical extortion structure. Victims are accustomed to receiving ransom notes from their attackers. They're not accustomed to receiving what amounts to a cleanup crew invoice from a third party claiming insider access to criminal infrastructure.


The fee range — $20,000 to $60,000 — is deliberately calibrated. It's low enough to feel like a bargain compared to a multi-million-dollar ransomware demand, and high enough to suggest seriousness. It's the pricing psychology of a secondary predator who understands its prey has already been softened up.


## What "Proof" Actually Means Here


Here's the core problem defenders need to internalize: there is no enforceable verification mechanism.


If you pay a ransomware group and they give you a decryption key, you can test whether it works. The deliverable is demonstrable. If you pay Ransom Busters $40,000 to "delete" your data from a server you've never seen, what exactly are you buying? A screenshot of a terminal? A promise from a criminal?


This is the double-verification problem. Even if Ransom Busters genuinely did access ransomware infrastructure — and that's an enormous "if" — there's no way for the victim to confirm deletion occurred, no way to confirm the data wasn't copied elsewhere first, and no way to confirm Ransom Busters won't re-approach you in six months with the same offer.


The ransomware industry has run this play before in a different form. When double-extortion became standard — encrypt the files, *then* threaten to publish the exfiltrated data — defenders quickly learned that paying the ransom didn't guarantee silence. Some groups published anyway. Some sold data to other actors. The payment was a gesture toward good faith that the receiving party wasn't obligated to honor.


Ransom Busters is exploiting that same trust vacuum, except they're operating entirely in the secondary market.


## Who Is Actually Behind This


The GuidePoint framing calls Ransom Busters a "ransomware affiliate," which is the detail that matters most and that other coverage is likely to gloss over.


Ransomware-as-a-service affiliates are the people who actually deploy ransomware — they license the malware from core developers, run the operations, and split the proceeds. An affiliate with access to the parent group's data exfiltration infrastructure isn't some outside hacker who cracked into Black Hat servers. They're an insider operating within, or adjacent to, that criminal ecosystem.


This opens several possibilities. Ransom Busters could be:


  • An active affiliate running an unauthorized side operation using data access they legitimately have
  • A former affiliate who retained infrastructure credentials after separating from the group
  • An affiliate operating with tacit group approval, effectively expanding the victim monetization surface
  • A fraud: someone impersonating an insider to collect payment without any actual access

  • The fourth option is the most dangerous for victims because it means paying achieves nothing except depleting cash that could fund actual incident response.


    ## HackWire Analysis


    What Ransom Busters represents isn't a novel scam — it's the logical endpoint of ransomware's maturation as an industry. As ransomware groups have professionalized, building customer service portals and negotiation teams, they've also created infrastructure complex enough that secondary actors can orbit them.


    The timing matters. We're in a period where victim organizations have become more sophisticated about ransomware response: cyber insurance is normalizing, incident response retainers are common, and law enforcement is offering occasional decryption keys post-seizure. The primary ransom business is facing more friction. Ransom Busters is capitalizing on a market inefficiency: the emotional state of a breach victim who has already paid (or is considering paying) and is desperate for any action that feels like control.


    The deeper pattern here parallels the fake "data removal" services that emerged after major data broker breaches — legitimate-sounding cleanup operations that collected fees without delivering outcomes. The credential is the claimed access, and the claimed access is unverifiable.


    For defenders, the playbook is frustratingly simple: do not engage. Do not pay. Route any unsolicited contact claiming insider access to ransomware infrastructure directly to your incident response team and to law enforcement (FBI IC3, CISA). Engagement, even to assess legitimacy, confirms you're an active target and may escalate contact.


    The harder truth is that no third party — not a consultant, not a self-proclaimed hacker collective, not a "recovery" service — can guarantee deletion of exfiltrated data. Once data leaves your network, you're managing exposure probability, not recovery. Organizations that haven't internalized this will remain the market for schemes exactly like this one.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)