FBI warns Silent Ransom Group targeting US law firms since 2023

Share:
Audio Loading voice…
FBI warns Silent Ransom Group targeting US law firms since 2023

Synopsis

The FBI has formally warned that the Silent Ransom Group — operating since Spring 2023 — is targeting US law firms using fake IT support calls, phishing emails, and even in-person office visits. Unlike typical ransomware gangs, SRG skips encryption entirely and goes straight for data theft and extortion, exploiting law firms' most sensitive client information as leverage.

Key Takeaways

The FBI issued a FLASH alert on 26 May warning that Silent Ransom Group (SRG) has targeted US law firms since Spring 2023 .
SRG — also known as Luna Moth , Chatty Spider , and UNC3753 — impersonates IT staff via phone calls, phishing emails, and in-person office visits.
Unlike traditional ransomware gangs, the group focuses on data exfiltration and extortion rather than system encryption.
Stolen data is transferred via tools like WinSCP and Rclone to platforms including Google Drive and Microsoft OneDrive .
The FBI recommends phishing-resistant multi-factor authentication , staff training, visitor identity verification, and restricted remote access permissions.

The Federal Bureau of Investigation (FBI) has issued a formal warning that a sophisticated cybercrime collective is systematically targeting US-based law firms, impersonating internal IT personnel through phone calls, phishing emails, and even in-person office visits. The alert, published on 26 May, names the group as the Silent Ransom Group (SRG) — also tracked under aliases Luna Moth, Chatty Spider, and UNC3753 — which has been actively operating against American legal practices since Spring 2023.

How the Attack Unfolds

According to the FBI's FLASH alert, SRG operatives initiate contact either by calling employees directly or sending phishing emails that prompt staff to dial what appears to be an IT support line. Once a target is on the phone, the attacker instructs them to grant access to a remote desktop session — effectively handing over control of the machine.

'SRG actors either directly call or send phishing emails to urge employees to call the SRG actor posing as IT support,' the FBI stated. 'While on the phone, the SRG actor directs the employee to grant access to a remote desktop session.'

If remote access attempts are unsuccessful, the group escalates to physical intrusion. In this scenario, an operative visits the victim's office in person, telling staff they need to 'image the device or create a backup file to address potential impacts from the phishing email,' the FBI said.

Data Theft Over Encryption

What distinguishes SRG from conventional ransomware gangs is its deliberate avoidance of system encryption. Instead, the group prioritises 'rapid access to victim systems, immediate data exfiltration, and extortion through threats of public disclosure or sale of stolen data,' according to the FBI alert.

Once inside a network, attackers use tools such as WinSCP or concealed versions of Rclone to extract company data at speed. The stolen files are then transferred to cloud platforms including Google Drive and Microsoft OneDrive, making detection and recovery significantly harder.

Extortion Tactics and Victim Pressure

After exfiltrating data, SRG actors contact both company employees and clients directly, threatening to publish or sell the stolen information unless a ransom is paid. This dual-pressure approach — targeting the firm and its clients simultaneously — is designed to accelerate negotiations and maximise leverage, particularly in the legal sector where client confidentiality is paramount.

Warning Signs and FBI Recommendations

The FBI's alert identified several red flags organisations should monitor, including unauthorised downloads of remote access software such as Zoho Assist, AnyDesk, RustDesk, Splashtop, and Atera. Suspicious cloud data transfers, installation of external hard drives, and unsolicited calls from individuals claiming IT affiliation are also flagged as indicators of compromise.

The agency urged organisations to reinforce cyber hygiene through staff training, regular data backups, and phishing-resistant multi-factor authentication. It also recommended verifying the identity of all visitors accessing company premises and restricting remote access permissions on systems that handle sensitive data.

With law firms holding some of the most sensitive client data in any industry — from litigation strategy to financial disclosures — the FBI's warning signals an escalating threat to the legal sector that shows no signs of abating.

Point of View

Client-sensitive, and legally privileged — making the threat of public disclosure an unusually potent extortion lever. The physical office visit escalation is the most underreported detail here: it signals a group with the operational confidence and resources to move beyond keyboards. For Indian law firms and professional services companies with US client exposure, this is not a distant threat — it is a template that will migrate.
NationPress
10 Aug 2026

Frequently Asked Questions

What is the Silent Ransom Group (SRG)?
The Silent Ransom Group (SRG) is a cybercrime collective, also tracked as Luna Moth, Chatty Spider, and UNC3753, that has targeted US-based law firms since Spring 2023. The group uses social engineering — fake IT support calls, phishing emails, and in-person office visits — to steal sensitive data and extort victims.
How does SRG differ from traditional ransomware gangs?
Unlike conventional ransomware groups, SRG does not primarily encrypt victim systems. Instead, it focuses on rapid data exfiltration and then extorts victims by threatening to publish or sell the stolen information publicly.
What warning signs should law firms watch for?
The FBI flagged unauthorised downloads of remote access tools such as Zoho Assist, AnyDesk, RustDesk, Splashtop, and Atera, along with suspicious cloud data transfers, external hard drive installations, and unsolicited calls from individuals claiming to be IT support staff.
What does the FBI recommend to protect against SRG attacks?
The FBI recommends phishing-resistant multi-factor authentication, regular data backups, staff cybersecurity training, verification of all visitor identities on company premises, and restricting remote access permissions on systems that handle sensitive data.
Why are law firms specifically targeted by SRG?
Law firms hold highly sensitive client data — including privileged communications, litigation strategy, and financial records — making the threat of public disclosure an especially powerful extortion tool. The FBI's alert notes the group has consistently focused on the US legal sector since at least Spring 2023.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 3 weeks ago
  2. 1 month ago
  3. 4 months ago
  4. 4 months ago
  5. 9 months ago
  6. 10 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google