{
  "id": 2166932,
  "title": "Scammers pose as ransomware recovery agents, but just go on to steal more from victims",
  "url": "https://urgent.news/2026/08/20/scammers-pose-as-ransomware-recovery-agents-but-just-go-on-to-steal",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T15:30:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/scammers-pose-as-ransomware-recovery-agents-but-just-go-on-to-steal-more-from-victims"
  },
  "original_language": "en",
  "account": "Ransomware attackers have developed a new tactic, posing as ransomware recovery agents, to steal more money from victims. GuidePoint Security, a cybersecurity firm, observed this phenomenon after being called to multiple ransomware attacks on their clients. The attackers, posing as \"Ransom Busters\", offered to delete stolen files from the attackers' servers and provide decryption keys for $20,000 to $60,000. However, researchers believe that Ransom Busters are likely just affiliates of the ransomware services, rather than genuine recovery firms, and are possibly even the ones who initially infected the companies. The firms using the same software, tactics, and identifiers suggest that it is the same group behind both the ransomware attacks and the supposed recovery. Fortunately, no one has paid Ransom Busters for their offer, and the victim who paid the actual ransom demand had their files remain secure.",
  "summary": "Ransom Busters are not an actual ransomware recovery firm - they're ransomware affiliates looking to steal your money, too.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}