A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with. Researchers at GuidePoint Security say an outfit calling itself "Ransom Busters" has been contacting ransomware victims before their attacks become public, offering to recover encrypted files and delete stolen data for a considerably smaller payment than the original extortion demand. The catch, according to GuidePoint's Research and Intelligence Team (GRIT), is that Ransom Busters isn't an enterprising band of ransomware hunters at all. The researchers assess with "moderate confidence" that it's a ransomware affiliate working across several ransomware-as-a-service operations and attempting to steer payments away from its criminal partners. GuidePoint came across Ransom Busters while investigating attacks linked to DragonForce, Settra, and Anubis. The outfit emailed victims claiming it had hacked the ransomware gangs themselves and discovered their stolen data on the crooks' servers. Ransom Busters claimed it could delete that data and retrieve encryption keys, all for the bargain-basement price of between $20,000 and $60,000. It also demonstrated access to the same datasets held by the ransomware affiliate behind the attacks, GuidePoint said. That alone raised eyebrows, but the forensic evidence proved rather harder to explain away. GuidePoint examined two incidents in which Ransom Busters approached victims and found the intrusions shared a collection of unusually specific fingerprints. Both used SoftPerfect Network Scanner for reconnaissance, s5cmd to shovel data into AWS cloud storage, and the Remotely remote-management tool installed using PowerShell. More damningly, the attacker created a local backdoor account using the password "Numlock!123" in both environments. The same attacker-controlled hostname, "DESKTOP-BBETH6K," also turned up in both intrusions. This might be explained by ransomware operators sharing tools or a prebuilt attack environment. GuidePoint said it has seen the same activity across several separate RaaS programs, however, leading it to conclude that one affiliate is likely moonlighting across multiple gangs and then cutting its employers out of the payday. GuidePoint also warned that paying the supposed rescuers provides no assurance that stolen information will actually disappear. So if a mysterious stranger somehow knows you've been ransomwared before you've told anyone, and generously offers to make the whole problem disappear for $20,000, you may want to question how they got your number in the first place. ®
Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain with the subject line “Important Security Update Regarding Your Quest Data.” That missive opens with unwelcome news that “I am writing to inform you of a recent data security incident involving some of your personal information.” “On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident,” the email continues. “The incident arose from a vulnerability through our third-party service provider.” Exposed data “relates to records from before June 2025” and includes guests’ full name, plus what Quest described as “Your email and/or other contact details.” The Register asked the company for comment, and it told us “A small number of data entries also involve Date of Birth.” Which means whoever accessed this info is now in a decent position to attempt identity fraud. Quest did not, however, identify the third-party that was the source of the breach, how the breach happened, or the number of customers impacted by the leak. The company also ignored our question about the extent of the lost data. Quest started operating more than 30 years ago, so we’re keen to know how far back this leak goes. Quest operates over 120 properties, most in Australia, plus some in New Zealand and Fiji. The Register has found listings for Quest properties on popular third-party travel booking sites such as Expedia, Wotif, and Booking.com – suggesting overseas visitors who stayed in the company’s properties may also be at risk. The accommodation outfit told The Register it has contacted all affected guests, contained and fixed the leaky systems, completed remediation, commenced forensic investigations, and hired external cyber security and privacy advisers. This is a developing story and The Register will update it as more information becomes available. ®
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to Have I Been Pwned. RingCentral disclosed the breach on July 28 and said “it was the target of a sophisticated social engineering campaign” affecting a “limited portion of RingCentral customers.” The comms platform said that it promptly responded to the intrusion upon detecting it, “took steps to stop the unauthorized activity,” and immediately launched an investigation into the security incident with help from a “leading third-party forensic firm.” “We have not seen any new unauthorized activity since taking these remediation efforts,” the company added. RingCentral did not immediately respond to The Register’s request for comment on this story. We will update it as needed. While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by The Register. Screenshots of the post also circulated on social media. The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online. RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet. “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care,” the crims wrote on August 3. A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password. This same group, which security sleuth Dominic Alvieri says is his “top threat group and probably is for most analysts,” has hacked hundreds of organizations since the start of the year, including education tech firms that provide services for schools and universities along with healthcare-sector organizations. Recently, ShinyHunters dumped data stolen from Abbott’s cancer diagnostics business with the leak containing 10.9 million unique email addresses alongside personal and health information. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.® Editor's note: This story was amended post-publication with comment from ShinyHunters.