A ransomware recovery scam is one of the cruellest tricks in the cybercriminal playbook: your business gets hit by ransomware, you desperately search for help, and the person you hire to negotiate your way out is secretly working with the attackers — or running their own con entirely. A recent case involving a group calling itself "Ransom Busters" shows exactly how this works, and why small and medium businesses are especially vulnerable to being deceived at their most desperate moment.
What Happened and Why It Matters
Ransom Busters presented itself as a professional ransomware recovery and negotiation service. In reality, it was operated by a rogue affiliate — someone with insider knowledge of how ransomware gangs operate — who used that position to collect payments from victims while either pocketing the money or passing only a fraction on to the attackers. Victims paid for a service that either did nothing or actively made things worse.
This is not a one-off incident. The ransomware ecosystem has grown into a layered criminal economy, where developers licence their malware to affiliates who carry out attacks independently. Some of those affiliates eventually pivot to running recovery scams, using their knowledge of ransomware negotiation tactics to appear credible to panicked business owners. They know what victims want to hear, and they say it convincingly.
Why SMBs Are the Primary Target
Large enterprises typically have legal counsel, cybersecurity insurers, and incident response firms already on retainer. When ransomware hits, they have a process. Small and medium businesses almost never do. The immediate instinct is to search online for help, which is exactly how fraudulent recovery services get their clients.
The urgency of a ransomware situation also works in the scammer's favour. Ransomware gangs impose countdown timers and threaten to publish stolen data or permanently delete decryption keys. That pressure causes business owners to make fast decisions without proper due diligence. A professional-looking website, a few fabricated testimonials, and a confident voice on the phone are often enough to win the business.
What makes this particularly dangerous is that victims may not even realise they have been scammed. Some fake recovery firms do negotiate with attackers on the victim's behalf — they simply mark up the ransom significantly and keep the difference without disclosing it. The business gets its files back and assumes everything went as described.
How to Verify Who You Are Actually Dealing With
Before engaging any third party after a ransomware attack, take a few basic steps even under time pressure. Check whether the firm is endorsed by a recognised body such as CISA, the National Cyber Security Centre, or a reputable cybersecurity insurer. Look for verifiable case studies and ask for references you can independently contact. Be sceptical of any firm that contacts you first — legitimate incident response companies do not cold-call ransomware victims.
It also helps to have a sense of your threat landscape before an incident ever occurs. If your credentials, internal documents, or employee data have already been exposed on dark web markets or infostealer logs, attackers may already have access to systems you are not aware of. That prior exposure is often what enables a ransomware attack in the first place — and knowing about it early gives you time to respond on your own terms rather than someone else's.
Breachrr monitors breach databases, infostealer dumps, dark web marketplaces, public code repositories, and domain infrastructure specifically for SMBs, so you know what attackers can already see about your business. The earlier you find an exposure, the more options you have.
What Good Incident Preparation Actually Looks Like
The best defence against a ransomware recovery scam is never needing a recovery service in the first place. That means tested backups stored offline, multi-factor authentication across all accounts, and a clear, written plan for who to call and what steps to take if an attack occurs — decided calmly in advance, not under duress.
It also means ongoing visibility into what data about your business is already circulating in places attackers frequent. A ransomware recovery scam exploits panic, and panic is reduced when you already understand your risk profile and have taken steps to address it.
If you want to understand what attackers might already know about your business before an incident forces the question, run a free audit at breachrr.com/audit.
Want to see if your company is exposed?