Ransomware Scam Group Claims It Can Help Delete Stolen Data, but Turns Out to Be a Double-Extortion Scheme

Views: 38 views

451/69 Thursday, August 20, 2026

Cybersecurity experts have identified a shift in ransomware-related threats, with the emergence of a group calling itself Ransom Busters. The group sends emails to organizations that have already fallen victim to ransomware attacks, claiming that it can breach the attackers’ servers and help delete the stolen data in exchange for a fee of approximately USD 20,000 to USD 60,000. However, researchers’ analysis indicates that this is likely a scheme operated by the same threat actors or individuals connected to the ransomware ecosystem, designed to extort victims a second time. The broader ransomware landscape has also seen the growth of new threat groups and a shift from file encryption to data theft and high-value extortion, affecting organizations across multiple sectors, particularly financial institutions, law firms, and large enterprises.

Analysis of ransomware operations such as Akira shows that attackers often begin by password-spraying VPN systems and gaining access through SSLVPN environments that do not enforce multi-factor authentication (MFA). They then conduct internal reconnaissance via RDP on domain controllers and collect data for exfiltration to cloud storage services such as AWS S3. To evade detection, attackers may reboot systems into Safe Mode to disable security tools before deploying ransomware. In some cases, even when the encryption stage fails due to system limitations, the data has already been successfully stolen. Statistics on ransomware groups with the highest number of victims in July 2026 show that The Gentlemen and Qilin were among the most active groups, with 138 and 133 victims respectively. This reflects the increasing use of multipurpose tools, Ransomware-as-a-Service (RaaS), and Hacking-as-a-Service (HaaS) models to improve attackers’ ability to gain system access.

To reduce the risk from this threat, administrators and organizations affected by ransomware should recognize that they should not cooperate with or pay individuals claiming they can help delete stolen data, as there is no evidence to verify their trustworthiness and such claims may simply be part of a secondary extortion scheme. Organizations should also strengthen basic security measures, including enforcing multi-factor authentication (MFA) for all internal access and VPN connections, reviewing accounts for suspicious or unauthorized users, and monitoring for large-volume data transfers to external cloud services. These measures can help detect and contain incidents at an early stage of an attack.

Source: https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html