Back to all lessons
Awareness Lessons
2 months ago

Ransomware Actor Masquerades as Recovery Service to Divert Ransom Payments

A ransomware affiliate operating as 'Ransom Busters' is impersonating a legitimate incident recovery service to deceive victims into paying ransom directly to them rather than the original threat actor. This social engineering tactic exploits the panic and confusion that follows a ransomware attack, when victims are desperate for help and may not thoroughly vet who they are dealing with. The scheme not only diverts funds but can also compromise the actual recovery process, leaving victims without decryption keys while still losing money. This highlights the critical importance of pre-establishing trusted incident response relationships before a crisis occurs, rather than searching for help in the aftermath of an attack.

Tactical Insight

Immediate actions

  • Verify the identity and credentials of any incident response or recovery vendor through official channels, references, and public reputation before engaging.
  • Contact your cyber insurance provider or legal counsel immediately after an incident to obtain pre-vetted, trusted IR vendor referrals.

Long-term improvements

  • Establish and document relationships with reputable, vetted incident response firms as part of your Incident Response Plan before any attack occurs.
  • Train employees and security teams to recognize social engineering tactics targeting organizations during crisis situations.
  • Maintain an updated Incident Response Plan that includes a pre-approved vendor list and clear escalation procedures.

Detection measures

  • Monitor threat intelligence feeds and industry advisories for known fraudulent recovery services and scam operators.
  • Require dual authorization from senior leadership and legal counsel before any ransomware-related payments or vendor engagements are approved.