Incident Response Services Now Have to Prove They Are Real
A ransomware affiliate has been posing as a rescuer, re-extorting its own past victims before they even go public. Here is what that does to every genuine vendor selling safety for a living.
By Katie Delaney · 2026-08-21 · 13 min read
When the rescuer turns out to be the raider#
A fox does not knock twice. It reads the ground once, weighs what the tracks say, and moves. Breached organisations rarely get that luxury. In the hours after an attack, the phone starts ringing with offers of rescue, some genuine, most not, and this month one of them turned out to be the same predator circling back for a second bite.
On 18 August 2026, GuidePoint Security's GRIT research published its own threat research team's findings on a scheme it calls “Ransom Busters”: an outfit that contacts breached organisations before an attack goes public, poses as an independent data-recovery firm, and offers to delete stolen files, for a fee, before anyone else finds out. The pitch sounds like rescue. GuidePoint's research and intelligence team, GRIT, found the opposite.
Investigators traced identical tooling, SoftPerfect Network Scanner, s5cmd and Remotely RMM, plus a shared backdoor password (“Numlock!123”) and a repeating attacker hostname (“DESKTOP-BBETH6K”), across cases tied to three separate ransomware-as-a-service panels: DragonForce, Settra and Anubis. GRIT states, with moderate confidence, that Ransom Busters is one affiliate working several gangs at once, re-extorting the same victims it already robbed.
The ask lands between $20,000 and $60,000, the same range BleepingComputer confirmed when it covered the findings, and the timing is the sharpest part of the con. Outreach arrives before disclosure, while a victim is most rattled and least able to check a stranger's story against anything real. Coveware's Elizabeth Cookson, quoted in that coverage, called the pattern “much more concerning” than an ordinary chase for a payout, because interference on a non-public incident raises the odds a frightened executive pays twice for one breach.
Interference on a non-public incident increases victim risk.
Nobody has confirmed a Ransom Busters payment yet. One targeted organisation paid the actual ransomware operator instead, and its files stayed unpublished, which tells its own quiet story about who genuinely held the keys that week. But “nobody paid yet” is not the same as “nobody will,” and the wider pattern underneath, criminals posing as the cavalry, is not new. It is just rarely camouflaged this well, and it lands squarely on the desk of anyone shopping for incident response services in the worst week of their working year.
Why the timing is the whole trick#
A genuine incident response firm gets a call, checks a contract, and starts a clock. Ransom Busters skips the checking. It already has the scent, because it planted the breach in the first place, and it uses that head start to reach a victim before the victim has even briefed a lawyer. Speed reads as competence when you are drowning. Here it is camouflage, the same predator wearing a rescuer's coat and hoping nobody looks too closely at the stitching.
The pattern behind the panic, proven live this week#
Re-victimisation has a paper trail well beyond this one scheme. On 20 July 2026 the FBI's Internet Crime Complaint Center issued FBI IC3 PSA I-072026-PSA, warning that criminals were impersonating the Bureau and IC3 itself, deepfake videos of senior officials, spoofed lookalike sites, cloned voices, to approach past fraud and scam victims a second time with an offer to recover money that was never coming back.
That advisory is not a ransomware-recovery warning specifically, it names a different scheme aimed at a different set of victims, so folkfox is not stretching it to fit. What it shares with Ransom Busters is the shape underneath: find someone who has already lost something, wear a badge you have not earned, and knock while they are still frightened.
A suspected ransomware affiliate is running a scam called Ransom Busters, posing as a legitimate recovery firm to double-dip on victims. Never engage with a recovery firm that contacts you first. Always verify credentials through established incident response channels (e.g., your insurer, legal counsel, or known IR firms). Maintain offline backups. If you have clean backups, you don't need to negotiate with anyone.
That reaction, posted within a day of GRIT's write-up, lands on the exact same advice the researchers themselves gave: verification is not paranoia, it is procedure. It is also, not coincidentally, the pitch every serious vendor of incident response services should already be making, because a buyer who has just watched a fox pose as a farmhand is not going to take the next knock at face value either.
This week supplied its own live case study in why the claim on the page matters less than the proof behind it. Late on 20 August, LockBit added US Bank to its leak site, alleging a breach and setting a deadline of 3 September, a fourteen-day pay-or-leak window, according to The Register. US Bank's Lee Henderson confirmed the bank is “aware of claims regarding a potential cybersecurity incident” while stating there is “no evidence of unauthorized access” to its network.
LockBit has overstated a claim before: in June 2024 it announced a 33-terabyte haul from the US Federal Reserve, and TechTarget's reporting later traced the actual leaked files to a single banking client, Evolve Bank and Trust, not the Fed at all. A line on a leak site is marketing copy written by criminals. It earns the same scrutiny folkfox would give any unverified statistic before printing it.
None of this proves LockBit is lying about US Bank, any more than it proves Ransom Busters is wrong about a given victim's breach. The point is narrower and more useful: an unverified claim, whichever direction it points, is a starting position, not a fact, and treating it as settled before checking is exactly the reflex both cons are built to exploit.
The money at stake, side by side#
Put the numbers next to each other and the con becomes obvious. A fake recovery firm asking $20,000 to $60,000 to “delete” data it never proved was destroyed sits in the same currency as the real damage ransomware does at scale, and drawing both on one chart is the quickest way to see why buyers of incident response services are done taking a promise on faith.
Scale changes the argument. A rescuer asking $20,000 to $60,000 while the confirmed damage runs into eight figures is not a bargain, it is a second predator working the same wound, and the gap between those numbers is precisely why a buyer cannot eyeball its way to trust. Real incident response services firms carry insurer relationships, named breach histories and retainer paperwork that predates the crisis. A scam has none of that, because building it takes longer than a con can survive.
Cheap does not mean safe, and expensive does not mean legitimate either#
The uncomfortable corollary is that price alone tells a buyer nothing. Firms like Coveware, which negotiates and tracks ransomware payments for a living, exist precisely because the market has learned that a fast, cheap promise is not the same thing as a safe one. Genuine incident response services are not defined by being expensive, they are defined by being provable, checkable against a public track record rather than a stranger's word delivered at the worst possible moment.
Buyers shopping for cybersecurity incident response services now read a vendor's homepage the way a fox reads a hedgerow, alert for the one gap that does not fit the pattern. A named client, a dated case study, a licence number that resolves on a public register: small, checkable, boring details, and every one of them a scent trail a scam cannot fake without months of preparation it does not have time to do.
How buyers actually judge incident response services now#
So what actually proves a firm is real, and not a fox in a rescuer's coat? CISA's own guidance built exactly this checklist into its Incident Response Plan basics: name an outside technical resource before you need one, brief your attorney on how you expect to engage that firm and law enforcement, and rehearse the relationship with a tabletop exercise long before a crisis forces the introduction.
US organisations hit by LockBit since January 2020
That figure is not a scare number, it is the size of the market a genuine vendor of incident response services has to prove itself against. A buyer vetting a stranger who just knocked should ask for the same things an insurer would ask for: named case studies with checkable details, a retainer that states response-time service levels before the meter starts running, and a point of contact who was on the payroll last month, not one who appeared the day the leak site listing went up.
The five-stage shape underneath most incident response plan templates, CISA's StopRansomware Guide's own included, traces back to NIST SP 800-61, the guide that first formalised the lifecycle for federal agencies and has anchored nearly every private-sector plan since.
Named vendor, tested backups and a written plan, agreed before anything goes wrong.
Confirm an incident is genuinely underway, and by whom, rather than reacting to an unverified claim.
Stop the bleeding: isolate affected systems without destroying the evidence a recovery will need.
Remove the attacker's foothold entirely, then restore systems from clean, tested backups.
A blameless retrospective that feeds straight back into preparation for the next one.
This is also, bluntly, the sales brief for every legitimate provider of managed detection and response, soc as a service or incident response services reading this. The scam did the positioning work for you: buyers who have watched a fake rescuer get named in trade press are primed to reward whoever proves credentials fastest and most plainly. Vague confidence is now a liability, not a selling point.

The vetting work is not exotic. the National Cyber Security Centre and the UK's CISA's StopRansomware Guide both describe the same discipline in slightly different words: preparation is the one thing that actually helps once the incident is live, and preparation includes deciding, in daylight, who you will trust in the dark.
Trust is the new pitch for security vendors#
None of this is abstract for a marketing team selling security services into a nervous market. The old pitch, fast response, deep bench, twenty-four-hour hotline, is table stakes now, the minimum any vendor claims whether or not it is true. What actually moves a buyer who has just read about Ransom Busters is proof they can check without picking up the phone: named clients where the engagement is a matter of record, credentials a prospect can verify against a public register, and retainer terms published plainly enough that a frightened CISO can compare two vendors at 2am without calling either one.
Trust signals are the differentiator, not the technical spec sheet#
Every serious vendor already has the detection tooling. What separates the ones winning new retainers from the ones losing pitches to a scarier headline is whether their site, their sales deck and their first email read like something a wary buyer could verify inside five minutes. That is a content and positioning problem before it is anything else, and it is exactly the brief folkfox builds for clients selling into cybersecurity: SEO and GEO pages that state credentials plainly, brand strategy work that names the licence and the track record instead of hinting at it, and a cybersecurity marketing programme that turns a checkable case study into the reason a nervous prospect calls you first.
The fox that survives a hard season is not the boldest one in the wood, it is the one whose scent the rest of the pack has learned to trust on sight. That is the whole game now for anyone selling incident response services: stop competing on who sounds most reassuring, and start competing on who is easiest to check. A buyer who has just watched a criminal borrow a rescuer's coat is not going to reward the next vendor for confidence alone.
If your own incident response plan still names a vendor nobody on the team has met, or your cybersecurity marketing pages read like every competitor's, that is the gap worth closing before the next headline does it for you. folkfox builds the brand work and the search visibility that make a genuine incident response services provider look, and read, like one.
A patient prowl beats a panicked pounce, on both sides of this trade. The scam artist needs a victim to decide fast, in fear, before the facts settle. A genuine vendor of incident response services wants exactly the opposite: a buyer calm enough to check the den before walking in, to follow the trail of references back to a real client rather than a plausible story, and to trust the firm that welcomes the scrutiny over the one that rushes past it. That is not a soft point about brand warmth, it is the actual, measurable difference between a retainer signed in confidence and a wire transfer sent in fright.
Frequently asked questions#
What are the 5 steps of incident response?
Most incident response guidance, including CISA's own StopRansomware Guide, breaks the work into five stages: preparation, identification, containment, eradication and recovery handled as one operational push, and lessons learned. Preparation happens before anything goes wrong; the rest happen in order once it has.
How do I know if a firm contacting me about a breach is legitimate?
Never trust the first message. Verify through a channel you already control, your insurer, your lawyer or a known incident response services provider, rather than a number or email in the outreach itself. GuidePoint's GRIT team found ransomware affiliates posing as recovery firms specifically because victims skip this step under pressure.
What is the difference between managed detection and response and incident response services?
Managed detection and response watches for threats continuously and alerts on them. Incident response services are engaged once something has already happened, to contain, investigate and recover. Many vendors sell both, and buyers should ask which retainer actually covers a live breach before assuming either does.
How much does resolving a ransomware attack actually cost?
There is no single confirmed figure for a typical case, but CISA has tracked around $91 million paid to LockBit alone by US victims since January 2020, across roughly 1,700 attacks. That is before recovery, legal and reputational costs, which do not appear in a ransom figure at all.
What should an incident response plan actually include?
CISA's own guidance lists a formally approved written plan, named roles for an incident manager, technical manager and communications manager, a pre-agreed outside technical resource, and a scheduled quarterly review. An incident response plan nobody has rehearsed is a document, not a defence.
Is it confirmed that LockBit actually stole US Bank's data?
Not as of publication. LockBit added US Bank to its leak site on 20 August 2026 and set a 3 September deadline, but US Bank states it has found no evidence of unauthorised network access. LockBit has overstated a breach claim before, so the claim alone is not proof either way.
Read more on this topic#
Nobody Exploited a Single Flaw. They Just Used the Password
A real MDR breach case study on what actually stops an intrusion, credentials over cleverness.
Read the piecePatch Tuesday, Exploited Wednesday
The buyer-proof case for vulnerability management services when exploit windows keep shrinking.
Read the pieceTwenty Five Days Until the Cyber Resilience Act Starts Counting Hours
The incident-reporting clock the CRA adds on top of everything covered here.
Read the pieceThe ICO Picked Reprimands Over Fines
How a regulator actually responds once a breach is confirmed, the other side of this story.
Read the piece
Ready to look as trustworthy as you actually are?
folkfox builds the brand strategy and search visibility that let a genuine incident response services provider prove itself in the first five minutes, not the fifth call.