HomeIntelligenceBrief
BREACH BRIEF🟠 High Ransomware

Ransom Busters Offers Paid Data Deletion After Ransomware Attacks, Demanding Up to $60K

A ransomware affiliate named Ransom Busters is emailing victims, claiming it can erase stolen data from ransomware servers for fees between $20K and $60K. The tactic highlights gaps in phishing defenses and SOC 2 incident‑response readiness.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 thehackernews.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Ransom Busters Offers Paid Data Deletion After Ransomware Attacks, Demanding Up to $60K

What Happened – A ransomware‑affiliated group calling itself Ransom Busters began emailing victim organizations, claiming it has compromised ransomware gangs’ command‑and‑control servers and can delete stolen data for a fee ranging from $20 K to $60 K.

Why It Matters for Compliance & Audit Readiness

  • The unsolicited offers are a classic phishing/social‑engineering vector that tests an organization’s email‑security controls and user awareness.
  • SOC 2 CC6.1 (Incident Response) and CC6.2 (Communication) require documented processes for handling ransomware extortion and third‑party threat‑actor interactions; this scenario underscores the need for exercised, auditable playbooks.
  • Continuous evidence of security‑awareness training and phishing‑simulation results provides defensible audit evidence that the organization mitigates this type of threat.

Who Is Affected – Enterprises across finance, healthcare, SaaS, and other sectors that have been targeted by ransomware gangs.

Recommended Actions

  • Map the phishing‑email scenario to SOC 2 CC6.1/CC6.2 controls and update your incident‑response playbook to include “ransom‑extortion‑service” communications.
  • Deploy or refresh security‑awareness training focused on ransomware‑related phishing, and run regular simulated phishing campaigns.
  • Capture and retain evidence of email‑filtering logs, training completion, and incident‑response drills for audit review.

Source: The Hacker News

Technical Notes – The affiliate uses bulk phishing emails (no disclosed CVE or exploit). The threat leverages stolen ransomware data rather than a new vulnerability; the primary vector is credential‑theft via deceptive email. Source: same as above

📰 Original Source
https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →