# Researchers link fake recovery service to ransomware affiliate

_Published Wednesday, August 19, 2026 at 9:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Researchers link fake recovery service to ransomware affiliate — Primary](https://www.bleepstatic.com/content/hl-images/2026/03/20/Extortion_hacker_scammer.jpg)

GuidePoint Security's GRIT says a suspected ransomware affiliate has posed as a recovery service called Ransom Busters, contacting victims before attacks became public and offering decryption keys and data deletion for $20,000 to $60,000. GRIT found overlapping tools, tactics, a backdoor account password and an attacker-controlled hostname in two incidents, leading it to assess with moderate confidence that a single affiliate was seeking payments outside ransomware-as-a-service revenue sharing. Coveware confirmed handling at least one similar incident.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/)

---
Canonical: https://techandbusiness.org/newswire/qaMAFMNDL0XSvy0iesxMxc
Published: 2026-08-20T01:07:48.698Z
Story chronology: 2026-08-19T20:59:58.000Z
Retrieved: 2026-10-04T21:07:07.743Z
Publisher: Tech & Business (techandbusiness.org)
