Do you have a ransomware recovery plan in place? Many might turn to "professionals" for help, but unfortunately, not all of them provide legitimate services. Learn more about the recent wave of ransomware recovery scams here.

Who Are the Ransom Busters?

Researchers from GuidePoint Security recently identified a group calling itself "Ransom Busters" that contacted ransomware victims and offered to recover files and delete stolen data from ransomware operators' servers. The group reportedly demanded $20,000 to $60,000 for its services.

Ransom Busters claimed it had breached the administrative panels of DragonForce, Settra, Anubis, and other ransomware-as-a-service (RaaS) groups. This access allegedly gave the group control over victims' stolen data and decryption keys.

A Ransomware Affiliate in Disguise

GuidePoint's team, however, noticed something unusual. Ransom Busters contacted some victims before their ransomware attacks became public knowledge. The researchers also found similarities between the supposed recovery operation and the original ransomware attacks, including overlapping tools, backdoors, passwords, and attacker-controlled infrastructure.

Based on those findings, cybersecurity specialists assessed with moderate confidence that Ransom Busters may actually be a ransomware affiliate rather than an independent recovery provider. The group could try to divert ransom payments or make additional money from the same victims it helped compromise.

Another Risk for Businesses

Cyber extortion already puts your company under serious pressure, and a fraudulent recovery offer can make matters worse. If you hand control to the wrong party, you could potentially face the following consequences:

  • Additional financial losses from fraudulent recovery fees
  • Further exposure of stolen business data
  • Unauthorized access to compromised systems
  • Additional theft of sensitive information
  • Confusion during ransom negotiations

You also won't know whether every copy of your stolen data has actually disappeared. Ransomware affiliates and other criminals may retain separate copies.

Spotting the Warning Signs of Scams and Fraud

How can you tell legitimate ransomware recovery services from a criminal posing as one? Start with the way they approach you.

They Contact You Out of the Blue

An unexpected recovery offer during an active ransomware incident deserves serious scrutiny. Legitimate incident-response firms generally provide services after an attack becomes known, while Ransom Busters contacted victims before public disclosure.

They Can't Verify Their Identity

Check the provider's domain, company registration, reputation, and contact information independently. Ransomware recovery scams may use a privacy-focused email address rather than a verifiable corporate domain.

They Demand Payment Immediately

Ransom Busters allegedly requested $20,000 to $60,000 early in its communications. Legitimate incident response providers typically assess the incident and scope the work before providing a price.

They Request Cryptocurrency

Stay especially cautious when someone claiming to be a cybersecurity professional demands payment in Bitcoin. GuidePoint identified cryptocurrency payment requests as a strong warning sign in this case.

Stay Alert When Seeking Ransomware Recovery

A ransomware attack can put your business under immense pressure, but don't let this urgency drive poor decisions that make you vulnerable to ransomware recovery scams. Always take the time to verify incident recovery providers before granting network access or sending payment.

Used with permission from Article Aggregator