When the ransomware rescuer is the attacker

· · Security

Picture the worst week your business could have. Your files are encrypted, your systems are down, and you are staring at a ransom demand. Then an email arrives from a security company you have never heard of. They know about the attack, which is odd, because you have not told anyone yet. They say they have hacked the criminals' own servers, found your stolen data, and can get your files back and delete every copy, for a fee. It reads like a lifeline. It is the attacker, wearing a different hat.

What investigators found

Incident responders at GuidePoint Security documented exactly this pattern across several recent ransomware cases. An outfit calling itself "Ransom Busters" emailed victim companies, asking to speak to the CEO or IT leadership. It claimed to have found vulnerabilities in the administrative systems of several ransomware gangs, giving it control of "almost all of their infrastructure". For a payment of between $20,000 and $60,000, it offered to return files and delete the stolen data from the criminals' servers.

The first red flag is the timing. In the cases GuidePoint worked, the emails arrived before the attack was public knowledge. Legitimate security firms sometimes approach victims after an incident is disclosed, but nobody honest knows about your breach before you have told anyone.

The forensic evidence goes further. GuidePoint's investigators examined two networks where victims had been contacted by Ransom Busters, and found the intrusions matched in ways that ordinary attacks do not: the same three tools for scoping the network, stealing data, and keeping remote access, a backdoor account created with the identical password on both networks, and the same attacker machine name appearing in both. Their assessment is that Ransom Busters is not a rescue outfit at all, but a ransomware affiliate, one of the contractors who carry out attacks for the big gangs, quietly double-dipping by posing as the cure for the disease it spreads. The pattern appeared across attacks by three different ransomware operations, and the ransom negotiation firm Coveware confirmed it had seen the same approach in an incident of its own.

Why the trick works

A ransomware attack is engineered to produce panic, and panic makes people take help from whoever offers it first. The scam works because it arrives at the exact moment your judgement is most impaired, offering the two things you want most: your files back, and the stolen data gone.

It is worth being clear about what paying anyone in this position buys you. Nothing verifiable. GuidePoint's blunt conclusion is that no payment to any criminal party guarantees stolen data is deleted, and researchers have repeatedly found gangs keeping copies of "deleted" data for later sale or a second round of extortion. A promise to destroy data is the one part of any ransom transaction you can never check.

The deeper lesson is not about this one group. It is that the moment your business is visibly wounded, everyone who contacts you is a suspect, and the middle of the crisis is the worst possible time to be choosing who to trust.

The decision that defuses it

The defence costs nothing and takes an hour: decide who you would call before you need them.

Name your incident help now. That might be your IT provider, an incident response firm, your insurer's approved responders (most policies name a panel and some require you to use it), or all three. Write the names and numbers down, on paper, somewhere that still exists when your systems do not. If you have followed our earlier filing on the first five minutes of incident response, this is the same list.

Make "unsolicited rescuer" a named red flag. Tell whoever answers your public email addresses: anyone who contacts us offering breach recovery we did not ask for gets forwarded to the response lead and answered by nobody else. No negotiation, no "just hearing them out". If they knew before you told anyone, they were involved.

Report it rather than engage it. In the UK, that means your incident responders, Action Fraud, and the NCSC's incident reporting route. A business that pays a fake rescuer has paid a criminal twice: once in money, and once in confirmation that it pays.

Rehearse the recovery order, not just the contact list. NCSC's recovery guidance, which we covered in a previous filing, is built around knowing which parts of the business must come back first. A firm that knows its recovery order negotiates from a plan. A firm that does not negotiates from fear, and fear is exactly what this scam is priced against.

How Steelwise can help

Working out who you would call, what you would recover first, and what your insurer actually requires of you in an incident is the kind of planning review we do, calmly and in advance. Get in touch.

Further reading

← All filings