惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
博客园 - 司徒正美
博客园 - 【当耐特】
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
宝玉的分享
宝玉的分享
V
V2EX
S
SegmentFault 最新的问题
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
L
LangChain Blog
D
Docker
腾讯CDC

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
FBI warns criminals impersonating IT support to breach la...
Silviu STAHIE · 2026-05-28 · via Consumer Insights

The FBI has issued a new FLASH alert warning that the Silent Ransom Group (SRG) is impersonating internal IT personnel to infiltrate organizations, steal private data and extort victims without using the traditional ransomware encryption.

The threat actors, also tracked as Luna Moth, Chatty Spider and UNC3753, have targeted US-based law firms heavily since 2023. However, the FBI says the group has also targeted organizations in healthcare, finance and insurance with the help of complex social engineering operations.

Unlike other known ransomware gangs that lock files and demand payment for decryption keys, SRG actors are more interested in rapid access, data theft and extortion threats tied to public leaks or sales of stolen information.

Key takeaways

The Silent Ransom Group impersonates internal IT support staff.

Attackers use phishing emails and phone calls to trick employees into granting remote access.

Some attacks involve individuals physically visiting company offices.

SRG actors steal data instead of encrypting systems.

The FBI says law firms remain a primary target.

Legitimate remote administration tools help attackers evade antivirus detection.

The group threatens victims with public exposure of stolen information.

Who is the Silent Ransom Group?

The Silent Ransom Group, operating since at least 2022, differs from many ransomware operations by often skipping encryption entirely. Instead, attackers focus on stealing sensitive information and pressuring victims into paying extortion demands.

The FBI says the group has consistently targeted law firms since Spring 2023 because legal organizations store highly sensitive client data, contracts, litigation materials and confidential communications.

How the attacks work

The latest SRG campaign relies heavily on social engineering instead of malware exploits.

According to the FBI, attackers either call employees directly or send phishing emails that instruct victims to contact fake IT support representatives. Once communication begins, the threat actors persuade employees to install remote access software or grant remote desktop permissions.

In some cases, attackers escalate the operation by physically visiting company offices.

The FBI says individuals linked to SRG may appear in person and claim they need to image a device or create a backup because of a supposed phishing-related issue. The attackers then connect USB drives or external storage devices to exfiltrate sensitive data directly from victim systems.

“Once the threat actor obtains access to the victim’s device, they minimally escalate privileges and quickly pivot to data exfiltration without encryption. SRG actors use WinSCP (Windows Secure Copy) or a hidden or renamed version of “Rclone” to exfiltrate data. SRG actors also exfiltrate data to internal filesharing platforms such as Google Drive or Microsoft OneDrive,” the FBI FLASH advisory explains.

Why law firms are being targeted

Law firms hold large amounts of confidential information tied to litigation, mergers, contracts, intellectual property and client communications.

Instead of disrupting operations with encryption, SRG actors threaten to publish or sell stolen information online. The FBI says the group operates a leak site named business-data-leaks[.]com where stolen victim information may appear.

Attackers also reportedly pressure victims by contacting employees or even clients directly to intensify negotiations.

Moreover, this latest advisory comes almost one year to the day after the previous one regarding the same attacker. Evidently, this is a problem that’s not going away.

Indicators of compromise

The FBI identified several warning signs organizations should monitor closely.

Indicator Why it matters
Unexpected remote access software installations Unauthorized downloads or installations of remote administration tools may indicate an attempted intrusion.
Suspicious USB or external drive activity Unexpected external storage device connections on sensitive systems could signal data exfiltration.
Unusual cloud storage transfers Exfiltration to OneDrive, Google Drive, or external servers may indicate movement of stolen data.
Calls from fake IT support staff Employees should treat unsolicited calls from individuals claiming to work in IT as suspicious until verified.
Extortion emails or phone calls Victims may receive messages claiming data was stolen or threatening public disclosure.

FBI recommendations for organizations

The FBI urges organizations to strengthen social engineering defenses and identity verification procedures.

  • Verifying the identity of all individuals accessing company premises
  • Training employees to recognize phishing and impersonation attacks
  • Limiting access to sensitive data from insecure networks
  • Requiring phishing-resistant multi-factor authentication
  • Maintaining regular backups
  • Restricting remote access permissions
  • Blocking port 22 when operationally feasible
  • Limiting external drive installation permissions on sensitive systems

FAQ

What is the Silent Ransom Group?

Answer: The Silent Ransom Group is a cybercrime operation that steals sensitive data and extorts victims instead of relying primarily on ransomware encryption.


Why are law firms being targeted?

Answer: Law firms store highly sensitive legal and client information that attackers can use for extortion and public leak threats.


Does SRG use malware?

Answer: The group often relies on legitimate remote administration tools and social engineering instead of traditional malware.


How do attackers impersonate IT staff?

Answer: Attackers send phishing emails or make phone calls pretending to be internal IT personnel and convince employees to grant remote access.


What should employees do if someone claiming to be IT contacts them unexpectedly?

Answer: Employees should independently verify the person’s identity through official internal channels before granting access or installing software.