An unsolicited recovery firm that knows about a ransomware incident before it is public should be treated as part of the investigation. GuidePoint Security reports that “Ransom Busters” contacted victims during incidents and offered paid help. Its researchers assess with moderate confidence that the persona is a ransomware affiliate, rather than an independent rescuer.
The private knowledge is the warning sign
The offer included claims of access to stolen data and the ability to delete copies for $20,000–$60,000. Knowing a real filename or incident detail does not authenticate a recovery provider: it can also indicate access to stolen material. A promise to erase an attacker’s copies is not independently verifiable.
Preserve the message and contact your existing responder through the number or account already on file. Do not start a separate conversation simply to ask the sender to prove access. That can disclose what your team knows, who makes payment decisions, or which systems remain unavailable.
Recognize the offer without relying on the sender name

A message can change its company name, subject or address. This fictional example illustrates the pitch; it is not a recovered Ransom Busters email:
From: Recovery desk <help@[sender-domain]>
Subject: Help recovering your files
We located your company documents in a criminal archive. Our team offers a paid recovery service and can remove the copies. Reply for details.
The address above is deliberately nonfunctional. The combination to recognize is unsolicited contact, claimed inside knowledge and a paid promise of recovery or deletion. A professional signature, familiar incident detail or reassuring phone call does not replace independent verification.
Match the response to what you already did
| Your interaction | What to do next |
|---|---|
| Only received the email | Preserve the original with headers and route it to the incident lead. Receipt alone does not mean a new device infection. |
| Replied or joined a call | Record the timeline and what you disclosed. Let the incident lead manage further contact rather than continuing privately. |
| Sent files or credentials | List exactly what was shared, with whom and when. Have responders assess additional data exposure and revoke exposed credentials from a clean device. |
| Ran a proposed recovery tool | Stop using that machine for sensitive work. Preserve the tool’s name and origin and have your responder investigate the execution; do not run it on another host. |
| Made a payment | Contact the payment provider promptly about available reversal or fraud procedures. Preserve receipts and involve your established response and law-enforcement contacts. |
Give the incident lead a useful handoff
Prepare one short record containing the original message, full headers, sender and reply-to addresses, phone numbers, arrival time, claimed access, requested fee, files shared and actions taken. Use your team’s approved evidence channel. Forwarding sensitive attachments to a new “verification” service creates another disclosure.
If you need a responder, use independently obtained contact details and check the provider’s identity, scope of work and authorized points of contact. For an organization with an insurer or retained response firm, coordinate through that existing arrangement. Do not let the email’s deadline choose the responder for you.
Keep recovery, cleanup and stolen data separate
Restoring a backup, decrypting a file and removing malware are different tasks. None establishes that an outside party erased stolen copies. A working sample file also does not prove that a tool is safe for the remaining data. The Phobos recovery guide shows how to check a legitimate, documented decryptor against supported variants and test copies; it does not imply Ransom Busters was involved in Phobos cases.
The FTC warns that recovery scams can target people after an earlier loss. If money was sent, act promptly through the payment provider and official reporting channels, and be suspicious of a new person offering to recover that second payment for another upfront fee.
References
- Justin Timothy. Beware the Ransomware Rescuer: Ransom Busters. GuidePoint Security, August 18, 2026.
- Federal Trade Commission. Refund and Recovery Scams. Consumer Advice, December 2023; accessed September 7, 2026.

