{
  "id": 2155408,
  "title": "Ransomware crook poses as recovery firm to steal payments from fellow extortionists",
  "url": "https://urgent.news/2026/08/20/ransomware-crook-poses-as-recovery-firm-to-steal-payments-from-fellow-2155408",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T14:27:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/08/20/ransomware-crook-poses-as-recovery-firm-to-steal-payments-from-fellow-extortionists/5290344"
  },
  "original_language": "en",
  "account": "Ransomware crooks may be funding their operations by posing as recovery firms to scam victims, according to researchers at GuidePoint Security. The group claims a company called \"Ransom Busters\" has been reaching out to ransomware victims before their attacks go public, offering to recover encrypted data and delete stolen information at a fraction of the original ransom demand. However, GRIT researchers have moderate confidence that Ransom Busters is not an independent ransomware hunter, but rather an affiliate working with multiple ransomware-as-a-service operations. They suggest the affiliate attempts to divert payments away from its criminal partners by undercutting their extortion demands. Ransom Busters allegedly contacted victims, claiming it had infiltrated the ransomware gangs, discovered their stolen data on the crooks' servers, and could delete that data and retrieve encryption keys for a fee between $20,000 and $60,000. Researchers discovered the intrusions shared a collection of specific fingerprints, such as using SoftPerfect Network Scanner for reconnaissance, s5cmd for data transfer to AWS cloud storage, and the Remotely remote-management tool installed via PowerShell. Additionally, both incidents involved the creation of a local backdoor account using the password \"Numlock!123\" and the attacker-controlled hostname \"DESKTOP-BBETH6K\". GuidePoint warns that paying the \"rescuers\" does not guarantee the stolen information will disappear, and advises caution if an unknown entity offers to resolve a ransomware issue at a significantly reduced price.",
  "summary": "Because apparently even ransomware gangs can't trust the people they do business with",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Ransomware crook poses as recovery firm to steal payments from fellow extortionists",
        "url": "https://urgent.news/2026/08/20/ransomware-crook-poses-as-recovery-firm-to-steal-payments-from-fellow",
        "published": "2026-08-20T14:27:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}