Rogue ransomware affiliate poses as data recovery firm to steal payments
Summary
A ransomware affiliate is posing as a data recovery firm called "Ransom Busters." This actor contacts ransomware victims before their attacks are publicly disclosed, offering to provide decryption keys and delete stolen data for a fee. This tactic aims to profit from victims' distress and lack of immediate information.
IFF Assessment
This article describes a new tactic used by ransomware affiliates to exploit victims, which directly harms defenders and organizations.
Defender Context
This threat actor's new social engineering approach highlights the importance of verifying any third-party claims for data recovery, especially when dealing with ransomware incidents. Defenders should educate their teams and potentially incident response partners about this specific tactic to avoid falling victim to further exploitation after a breach.