Here is a new twist on an old nightmare. A group calling itself “Ransom Busters” has been emailing ransomware victims and offering to hand over decryption keys and delete stolen data for $20,000 to $60,000. The catch: they were contacting victims before anyone else knew the attacks had happened. GuidePoint Security’s research team dug in and concluded, as reported by Bleeping Computer, that Ransom Busters is almost certainly the ransomware affiliate that broke in, now trying to collect a second time by cutting out the gang it works for.
Same tools across the incidents. Same backdoor account with the password Numlock!123. Same attacker hostname showing up in the logs. That is not a recovery firm. That is the burglar calling to sell you back your own keys.
If you get hit, the first two days decide how bad it gets. Here is the order to do things in.
1. Do not reply to anyone who contacts you out of the blue
Nobody legitimate knows you were attacked before you announce it. If an email arrives offering keys, data deletion, or “negotiation help” while you are still figuring out what happened, that message came from someone with inside knowledge of the attack. Forward it to whoever is running your response and stop there. Coveware told Bleeping Computer that middlemen like this have been showing up since 2024, and this version, reaching out on incidents that were never public, is the worrying kind.
2. Disconnect, but do not wipe
Pull the affected machines off the network. Unplug the Ethernet, disable the Wi-Fi. Do not reimage them, do not “clean them up,” do not power everything off in a panic. Those machines hold the evidence that tells you how the attacker got in and whether they are still inside. Wipe the box and you lose that, and you get to be surprised again in three weeks.
3. Call your insurance carrier and your attorney before you call anyone else
Most cyber policies require you to use approved incident response and negotiation vendors. Hire someone on your own first and the carrier can refuse to reimburse it. One phone call, made early, protects the coverage you have been paying for.
4. Assume every credential is burned
Reset passwords for all admin accounts, revoke active sessions in Microsoft 365 or Google Workspace, and rotate any saved keys or service passwords. Then go looking for accounts the attacker created. In the Ransom Busters cases, that meant a local backdoor account on a compromised machine. Check local administrators on every server, check for new users in your identity system, and check for MFA methods added to existing accounts. Attackers frequently register their own phone number as a second factor so they can walk back in after you change the password.
5. Check your backups from a machine you trust
Verify the backups exist, then verify they restore. Modern ransomware crews hunt for backup servers and delete or encrypt them first, which is why the copy that matters is the one they cannot reach: offline, or in cloud storage with immutability turned on so it cannot be deleted for a set number of days. Getting that architecture right before an incident is most of the job, and it is exactly what a properly configured cloud backup is for.
6. Assume the data left the building
Encryption is the noisy half. Theft is the expensive half. Groups like DeadLock, which Microsoft describes as running its leak and negotiation infrastructure on decentralized services that are hard to take down, build their whole model around publishing what they stole. If you are a medical or dental practice, a law firm, or you handle payroll data, your notification clock may already be running. Get your attorney on the scope question early.
7. Do not pay the middleman, and think hard before paying anyone
GRIT says it has seen no victim actually pay Ransom Busters, and recommends nobody start. You would be buying a promise from the person who attacked you, with no leverage and no recourse. Even with the real gang, paying is a business decision made with counsel and your insurer, not a reflex at 11pm.
The part that happens before all of this
Every item above is damage control. The cheaper work is upstream: endpoint detection that flags the scanning and the new admin account while the attacker is still poking around (what we deploy and watch for clients), offline backups you have actually test-restored, MFA on remote access, and a short written list of who to call. We wrote a plain-English breakdown of what endpoint detection is and whether a small business needs it in an earlier post.
If you do not know today whether your backups would survive an attacker with domain admin, that is the gap to close this month. Book a free 15-minute consult and we will walk through it with you.