Ransom Busters Offers Paid Data Deletion After Ransomware Attacks, Demanding Up to $60K
What Happened – A ransomware‑affiliated group calling itself Ransom Busters began emailing victim organizations, claiming it has compromised ransomware gangs’ command‑and‑control servers and can delete stolen data for a fee ranging from $20 K to $60 K.
Why It Matters for Compliance & Audit Readiness
- The unsolicited offers are a classic phishing/social‑engineering vector that tests an organization’s email‑security controls and user awareness.
- SOC 2 CC6.1 (Incident Response) and CC6.2 (Communication) require documented processes for handling ransomware extortion and third‑party threat‑actor interactions; this scenario underscores the need for exercised, auditable playbooks.
- Continuous evidence of security‑awareness training and phishing‑simulation results provides defensible audit evidence that the organization mitigates this type of threat.
Who Is Affected – Enterprises across finance, healthcare, SaaS, and other sectors that have been targeted by ransomware gangs.
Recommended Actions –
- Map the phishing‑email scenario to SOC 2 CC6.1/CC6.2 controls and update your incident‑response playbook to include “ransom‑extortion‑service” communications.
- Deploy or refresh security‑awareness training focused on ransomware‑related phishing, and run regular simulated phishing campaigns.
- Capture and retain evidence of email‑filtering logs, training completion, and incident‑response drills for audit review.
Source: The Hacker News
Technical Notes – The affiliate uses bulk phishing emails (no disclosed CVE or exploit). The threat leverages stolen ransomware data rather than a new vulnerability; the primary vector is credential‑theft via deceptive email. Source: same as above