decrypted · 22 august 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law
The fake ransomware 'rescuer' that's really the same gang calling back
When a ransomware victim's phone rings a few days after the attack, the caller is meant to be an incident responder. This week, researchers at GuidePoint Security documented a group that has worked out how to make that call first, and get paid for it, without lifting a finger to fix anything. Calling itself "Ransom Busters", it contacts victims of established ransomware gangs before the attack is even public, claims to have hacked the criminals' own infrastructure, and offers to delete the stolen data and hand back the keys, for $20,000 to $60,000: a fraction of the original demand. There is no rescue on offer. GuidePoint's forensics show the same intrusion signatures, the same backdoor account password ("Numlock!123") and the same attacker hostname turning up across incidents attributed to three separate ransomware-as-a-service operations, DragonForce, Settra and Anubis. The conclusion: one affiliate, working several gangs at once, running a second extortion racket on the side.
The tell in the timing
The giveaway isn't the pitch, it's the clock. Legitimate recovery firms and law enforcement get involved once a breach is public or once a victim has called them in. Ransom Busters reaches out beforehand, which it can only do because it, or someone it works with, was inside the network. That's the equivalent of a burglar knocking the next morning dressed as a locksmith, offering a discount on fixing the door they kicked in themselves. The tooling matches too: SoftPerfect Network Scanner for reconnaissance, s5cmd to move data to attacker-controlled AWS storage, a remote monitoring tool dropped in through PowerShell. None of that belongs to a genuine recovery service; all of it belongs to the intrusion.
The Secure by Design lesson
The design failure here isn't technical, it's organisational: too many boards still don't have a pre-agreed answer to "who do we trust when someone contacts us claiming to help?" That answer needs to exist before an attack, not be improvised under pressure with a countdown timer and a chief executive's inbox. The NCSC maintains an assured Cyber Incident Response scheme precisely so organisations aren't choosing a responder for the first time mid-crisis. Any unsolicited offer of "recovery", especially one that arrives suspiciously early, should go straight to that pre-agreed responder and to law enforcement, not into a private negotiation. Paying a second extortionist doesn't undo the first extortion, and nothing here guarantees data is actually deleted rather than quietly kept for a third round.
Also this week
A perfect-ten flaw in Microsoft's identity backbone, fixed without anyone touching a keyboard. Microsoft disclosed CVE-2026-69836, a maximum-severity (CVSS 10.0) deserialisation flaw in Entra ID, the identity service behind Microsoft 365 and Azure sign-in for most large UK organisations, that let an unauthenticated attacker run code with no user interaction. It was already being exploited. The reassuring part is also the uncomfortable part: because Entra ID is a Microsoft-run cloud service, the company patched it centrally and says customers have nothing to deploy. Compare that with the on-premises SharePoint and vCenter flaws this column has covered this month, where every straggling install stayed exposed for as long as an admin hadn't acted. Centralised patching is a genuine Secure by Design win; it's also a reminder of how much trust UK organisations now place in a vendor's internal security, with almost no visibility into what happened before the fix landed.
The ICO spells out what "basic" security failure looks like. The regulator has reprimanded ACRO, the Criminal Records Office, over a breach running from 2021 to 2023 that exposed the data of up to 10,920 people, including passport, National Insurance and biometric details tied to child protection and criminal record checks. The cause wasn't sophisticated: ACRO ran an unpatched content management system for over three years because nobody was clearly accountable for applying updates, and antivirus alerts flagging the intrusion went unread. The ICO's line is worth repeating to any UK organisation handling sensitive personal data: assign patch ownership explicitly, and make sure someone is actually looking at the alerts your own tools are already generating.
Sources
- GuidePoint Security: Beware the Ransomware Rescuer: Ransom Busters
- The Register: Ransomware crook poses as recovery firm to steal payments from fellow extortionists
- Help Net Security: Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)
- The Register: Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack
- The Register: Exposed - woeful security at UK criminal records office that led to sensitive data leak
- Infosecurity Magazine: ICO Reprimands Criminal Records Office After 2023 Breach
Got a security question you'd like Decrypted to dig into? Get in touch.
More like this
- MikroTik routers are being hijacked exactly as NCSC warned they would be 8 september 2026
- CrowdStrike's macro clean-up tool turns into a SYSTEM shell 5 september 2026
- The UK just gave ministers a veto over your suppliers 2 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.