Hackers claim to have breached ransomware operations and now demand ransom from victims to delete stolen data.
In a development that reads like a heist movie, a group calling itself Ransom Busters claims to have successfully broken into the computer systems of ransomware operators—the very criminals who typically extort money from businesses and individuals. However, instead of simply destroying the stolen information, these digital vigilantes are now asking victims to pay between $5,000 and $60,000 for the deletion of their compromised data.
This creates an unusual and troubling situation: people who were already victimized by ransomware attacks are now potentially facing a second demand for payment from a different source.
At the same time this story is developing, security researchers have discovered serious safety gaps in two widely-used software tools. MLflow, a popular platform designed to help artificial intelligence developers manage their projects, and FUXA, a system used to control and monitor industrial machinery and utilities, both contain critical vulnerabilities—essentially unlocked doors in their digital infrastructure.
Attackers are actively scanning networks looking for these weak points and attempting to exploit them. This is particularly concerning because FUXA is used in operational technology environments, meaning the affected systems might include power plants, water treatment facilities, and manufacturing plants that affect the physical world.
Think of these vulnerabilities like finding a gap in your home's security system. Once discovered, criminals don't hesitate to test whether they can slip through. The fact that multiple threat actors are already probing for these weaknesses suggests that attacks could increase significantly in the coming days and weeks.
For companies using these tools, the risk is particularly acute because:
The emergence of Ransom Busters adds another layer of complexity. While their stated mission—stealing from cybercriminals—might seem appealing on the surface, it simply creates additional victims and perpetuates the extortion cycle. Companies that were already harmed by the initial ransomware attack now face pressure from a third party claiming possession of the same information.
This represents a concerning trend where even those attempting to counter cybercrime are themselves resorting to extortion tactics.
The cybersecurity landscape continues to evolve in troubling ways, reminding us that staying vigilant and proactive is the only reliable defense.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →