Cybersecurity — 2026-05-27

FBI Warns Silent Ransom Group Conducting In-Person Social Engineering Attacks and Data Theft at US Law Firms

BLUFFederal indictments against SRG members are unlikely before August 24, 2026, leaving law firms to absorb defensive costs of extending security controls into physical access domains.

The FBI issued a flash alert on May 26, warning that SRG actors pose as internal IT staff via phone or phishing email to coerce employees into granting remote desktop access to victim systems 123. When remote attempts fail, SRG sends an operative to the victim's office who claims a need to image or back up the system, then physically connects a USB drive or external hard drive to exfiltrate data 13. SRG subsequently extorts victims by threatening to publish or sell stolen data and directly contacts employees and clients of the target organization to pressure ransom negotiations 134. The FBI noted that SRG operations leave minimal forensic artifacts and evade antivirus detection by routing activity through legitimate tools including AnyDesk, Zoho Assist, WinSCP, and Rclone 34. SRG, also tracked as Luna Moth, Chatty Spider, and UNC3753, has operated since at least 2022, relies solely on data-theft extortion without ransomware encryption, and previously targeted insurance, finance, and healthcare sectors before intensifying focus on law firms 2.

Analysis
Federal charges against SRG members before August 24, 2026 are unlikely. The group has operated since at least 2022 without a single publicly disclosed indictment, its use of legitimate remote-access tools limits forensic artifacts available to prosecutors, and attribution of in-person operatives, who may be hired contractors, adds investigative complexity the FBI has not resolved. SRG's tactical shift to physical office access when remote attempts fail forces law firm security programs into physical access protocols historically left to building management. The tactic may be confined to a small number of high-value engagements, limiting its scalability. We hold moderate confidence, grounded in consistent multi-year FBI visibility into SRG operations but tempered by single-source reliance with no independent corroboration of prosecutorial timelines. Should charges materialize before August 24, firms can pause accelerated physical hardening; absent them, executive leadership must sustain that investment without expectation of near-term deterrence.
4 sources
  1. FBI warns of in-person data theft attacks from extortion gang - BleepingComputer
  2. Silent Ransom Group Impersonating IT Personnel through Social Engineering Campaigns - FBI / IC3
  3. Hackers are knocking on office doors pretending to be IT staff - Help Net Security
  4. FBI Alerts on Silent Ransom Group Targeting Law Firms - Halcyon

View in full brief →

UNCLASSIFIED // OPEN SOURCE