GuidePoint Research and Intelligence Team (GRIT) has documented a pattern in which ransomware victims receive unsolicited emails from a self-described third party calling itself "Ransom Busters," offering to help them recover from an ongoing attack. The contact arrives uninvited — typically after an incident is already underway — and GRIT flagged it as immediately anomalous. Healthcare organizations, which are disproportionately targeted by ransomware and under intense pressure to restore clinical operations quickly, are among the victim types most likely to consider such an offer.
What the scheme looks like
The core red flag is timing and method. Ransom Busters contacts victims who have not sought outside help, meaning the entity either monitors ransomware leak sites for newly named victims, maintains access to attacker communications channels, or has some other visibility into active incidents before victims have made the contact public. None of those explanations is benign.
The offer itself mirrors a known secondary-exploitation pattern: a victim in crisis is approached by a party presenting as a neutral rescuer, but whose actual role — whether acting as a covert intermediary who simply passes ransom payments to the threat actor while taking a fee, or as a second threat actor harvesting additional information about the victim's environment — is not what it appears.
Why this is particularly dangerous for healthcare
Healthcare organizations facing ransomware frequently operate under conditions that compress decision-making: patient care systems are down, staff are reverting to paper processes, and leadership is under regulatory clock pressure from HHS breach notification timelines. That environment creates openings for bad actors posing as expedient solutions.
A practice administrator or incident response coordinator who responds to a Ransom Busters email risks several outcomes:
- Disclosing internal incident details to an unknown party that could use them to refine extortion demands or identify additional exploitable data.
- Paying a fee to an intermediary who is, in effect, passing funds to the original threat actor — potentially implicating the organization in sanctions-related payment violations if the threat actor is a designated entity.
- Delaying legitimate incident response by engaging a channel that provides no actual technical recovery capability while authentic remediation work stalls.
What this signals about post-incident contact protocols
GRIT's documentation of multiple incidents suggests Ransom Busters is not a one-off phishing attempt but an active operation. The pattern points to a need for healthcare organizations to establish, in advance and in writing, exactly which parties are authorized to communicate on behalf of the organization during an active ransomware incident — and to treat any unsolicited recovery offer that arrives by email as a potential extension of the attack itself.
Incident response plans should specify that all third-party engagement offers received during an active incident are routed to legal counsel and the designated incident response firm before any response is sent. Staff with access to incident communications — including IT leadership, practice managers, and executives — should be briefed on this category of social engineering before an incident occurs, not during one.
Regulatory counsel familiar with OFAC's ransomware payment advisory framework should be part of any organization's pre-incident planning, given that covert intermediary payments can carry the same sanctions exposure as direct payments to a designated threat actor.