# Researchers link fake recovery service to ransomware affiliate

_Wednesday, August 19, 2026 at 4:59 PM EDT · Security · Latest · Tier 2 — Notable_

![Researchers link fake recovery service to ransomware affiliate — Primary](https://www.bleepstatic.com/content/hl-images/2026/03/20/Extortion_hacker_scammer.jpg)

GuidePoint Security's GRIT says a suspected ransomware affiliate has posed as a recovery service called Ransom Busters, contacting victims before attacks became public and offering decryption keys and data deletion for $20,000 to $60,000. GRIT found overlapping tools, tactics, a backdoor account password and an attacker-controlled hostname in two incidents, leading it to assess with moderate confidence that a single affiliate was seeking payments outside ransomware-as-a-service revenue sharing. Coveware confirmed handling at least one similar incident.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/)

---
Canonical: https://techandbusiness.org/newswire/qaMAFMNDL0XSvy0iesxMxc
Retrieved: 2026-08-20T01:35:05.948Z
Publisher: Tech & Business (techandbusiness.org)
