As cited
Citation snapshot as of .
ransomware
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is operating a fake recovery service called Ransom Busters, proactively contacting potential victims before attacks are disclosed and offering to provide decryption keys and delete stolen data in exchange for payment. This scheme exploits victims' desperation during the critical window between encryption and public disclosure.
Why it matters: Organizations hit by ransomware need to verify recovery service legitimacy before paying anyone, as fraudulent offers could result in double losses: the fake recovery fee plus ongoing exposure if the attacker retains access and data.
- Source published
- First seen by Cybersecurity Tracker