Proven Data A.I CyberSecurity Scoring
Proven Data
Company Information
Website:https://www.provendata.com
Employees number:33
Number of followers:1,662
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:provendata.com
Proven Data Risk Score (AI oriented)
Between 0 and 549
Proven DataIT Services and IT Consulting
Updated:
19/08/2026
19/08/2026
468/1000
Critical
C
Proven Data Global Score (TPRM)
xxxx
Proven DataIT Services and IT Consulting
Score locked

Proven DataCritical
Current Score
468C (CRITICAL)
01000
2 incidents
-197 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
472
AUGUST 2026
665
Ransomware
19 Aug 2026 • Proven Data
DragonForce and Settra: Ransomware Affiliate Poses as Recovery Firm to Re-Extort Victims After Data Theft
Ransomware Affiliates Pose as Recovery Services in New Extortion Scheme
468
CRITICAL-197
DRAPRO1787127993
Ransomware Affiliates Pose as Recovery Services in New Extortion Scheme
GuidePoint Security’s Research and Intelligence Team (GRIT) has identified a deceptive ransomware extortion tactic involving a group calling itself "Ransom Busters." The alleged recovery service contacts victims before their cyberattacks become public, offering to retrieve stolen files, destroy criminal backups, and provide decryption keys for a fee.
However, GRIT assesses with moderate confidence that Ransom Busters is actually a ransomware affiliate attempting to divert payments from the original ransomware operation. The scheme has been linked to incidents involving DragonForce, Settra, and Anubis ransomware activity.
### How the Scam Works
Instead of relying solely on a standard ransom note, the suspected affiliate presents itself as a third-party recovery service that claims to have breached ransomware gangs’ infrastructure. Victims receive emails from "Ransom Busters LTD" targeting CEOs or IT leaders, asserting that the group has found stolen company data on ransomware servers and can delete it for a price. The emails also claim access to encryption-key storage and administrative panels.
The tactic is suspicious because legitimate cybersecurity firms typically engage with victims after an incident becomes public. Ransom Busters, however, contacts organizations while attacks are still private, suggesting prior knowledge of the breach.
### Technical Evidence Links Affiliates to Multiple Ransomware Groups
GRIT analyzed two incidents where Ransom Busters approached victims and found multiple technical overlaps:
- Use of SoftPerfect Network Scanner for internal reconnaissance.
- Deployment of s5cmd to exfiltrate data to AWS cloud storage.
- Installation of Remotely (a remote monitoring tool) via PowerShell.
- Creation of a local backdoor account with the same password (Numlock!123) and hostname (DESKTOP-BBETH6K) in both intrusions.
While some indicators could reflect a shared ransomware playbook, their combined presence strengthens the correlation. GRIT noted that similar activity has appeared across multiple ransomware-as-a-service (RaaS) operations, making it unlikely that Ransom Busters is an independent recovery firm.
### Financial Demands and False Promises
The group demanded $20,000 to $60,000 to delete stolen data, claiming payment was necessary to maintain access to criminal infrastructure a claim GRIT found unconvincing, as a victim’s payment would not logically secure such access.
This case highlights an evolving ransomware model, where affiliates may re-extort victims independently after stealing data. By posing as a recovery service, the actor creates an alternative payment channel while exploiting victims’ fear of exposure. There is no guarantee that criminals will delete data after payment, as they may retain copies for future extortion or leaks.
Organizations receiving unsolicited recovery offers particularly those aware of a non-public breach should treat them as likely scams or additional extortion attempts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
664
JUNE 2026
662
MAY 2026
660
APRIL 2026
658
MARCH 2026
657
FEBRUARY 2026
655
JANUARY 2026
653
DECEMBER 2025
651
NOVEMBER 2025
649
OCTOBER 2025
647
JANUARY 2024
750
Ransomware
01 Jan 2024 • Proven Data
DragonForce and Settra: Rogue ransomware affiliate poses as data recovery firm to steal payments
Ransomware Affiliate Masquerades as Recovery Service in Sophisticated Extortion Scheme
591
CRITICAL-159
PRODRA1787174209
Ransomware Affiliate Masquerades as Recovery Service in Sophisticated Extortion Scheme
A suspected ransomware affiliate is targeting victims under the guise of a recovery service called Ransom Busters, contacting them before attacks become public and offering decryption keys and data deletion for a fee. GuidePoint Security’s Research and Intelligence Team (GRIT) uncovered the scheme after responding to multiple ransomware incidents where victims received unsolicited emails from the group.
Ransom Busters claimed to exploit vulnerabilities in ransomware-as-a-service (RaaS) administrative panels, granting access to encryption keys and stolen data from operations like DragonForce, Settra, and Anubis. The group demanded payments between $20,000 and $60,000 to delete data from ransomware servers. However, GRIT’s investigation revealed strong evidence linking Ransom Busters to the attacks themselves. In two incidents, the same tools (SoftPerfect Network Scanner, s5cmd, Remotely), tactics (including a backdoor account with the password Numlock!123), and attacker-controlled hostname (DESKTOP-BBETH6K) were used.
GRIT concluded with moderate confidence that Ransom Busters is a single ransomware affiliate attempting to divert ransom payments from RaaS gangs. While no victims have reportedly paid the group, one victim instead paid the RaaS operation behind the attack yet their data was not leaked, suggesting Ransom Busters may have complied with the agreement.
Ransomware negotiation firm Coveware confirmed encountering similar activity, noting this behavior differs from typical "ambulance chasers" who target publicly disclosed victims. Unlike those opportunists, Ransom Busters exploits non-public incidents, increasing risks for victims paying the ransom may no longer guarantee data deletion if multiple parties have access. Coveware warned that growing distrust within RaaS ecosystems could fuel more such schemes as affiliates seek additional profits outside standard revenue-sharing models.
The incident highlights an alarming evolution in ransomware tactics, where attackers not only encrypt data but also pose as recovery services to exploit victims before breaches are detected.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Proven Data ??
What was Proven Data's A.I Rankiteo Cyber Score in August 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in July 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in June 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in May 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in April 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in March 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in February 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in January 2026 ??
What was Proven Data's A.I Rankiteo Cyber Score in December 2025 ??
What was Proven Data's A.I Rankiteo Cyber Score in November 2025 ??
What was Proven Data's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Proven Data's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Proven Data ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Proven Data's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?