Back to The Local Vocal
The Local VocalHigh
Email
High risk 3rd Party Advisory 19 August 2026
RegionNew Zealand

Dodgy ransomware fixer wants you to pay

A self-described ransomware fixer is emailing organisations after attacks, claiming it can delete stolen data from criminal servers if you pay a large fee.

You could receive an email from a sender calling itself Ransom Busters, presented as a specialist recovery or negotiation service after a ransomware incident. The message claims your stolen files are sitting on a ransomware group’s servers and says it can get that data deleted for a fee. It pushes you to reply, engage directly, and arrange payment to solve the problem quietly.

What gives it away is the approach itself. Legitimate incident response providers do not normally appear out of nowhere after an attack, claiming they already have access to criminal infrastructure and offering paid deletion as proof of help. As researchers noted, the contact is anomalous, which in plain language means the message is not behaving like a normal, verifiable recovery service and you have no reliable way to confirm who is really behind it or whether their claims are true.

The attacker is after your money, your trust, and potentially more detail about your breach. If you engage, you could be pushed into paying a large sum to an unknown third party, reveal sensitive information about your systems, or be drawn into further extortion without any assurance that stolen data has been removed at all.

This is relevant to any NZ organisation dealing with ransomware fallout, especially if criminals believe you are under pressure to contain reputational damage. These approaches can keep appearing because they target businesses at their most vulnerable point, when urgency and uncertainty make unusual offers sound credible.

Source: The Hacker News — https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Review whether your organisation has any current or recent ransomware exposure that could make this approach relevant in your environment.
  • Check: Confirm your incident response, cyber insurance, and ransomware negotiation processes so staff know who is authorised to engage if any post-incident contact arrives by email.
  • Do not: Ignore vendor or agency advisories, prompt action within the recommended timeframe reduces exposure significantly.
  • Report: If this kind of contact is identified, notify your IT provider immediately, and report to NCSC NZ at report.ncsc.govt.nz if active exploitation or extortion is suspected.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.