Silent Ransom Group Posing as IT Support: The Office Security Threat of 2026
Hackers Are Now Knocking on Office Doors Pretending to Be IT Support — Google and FBI Issue Urgent Warning
A cybercriminal gang called Silent Ransom Group has added a genuinely alarming new weapon to its arsenal: sending fake IT workers to victims’ offices in person to steal data directly from computers using USB drives. Google and the FBI have both issued formal warnings. Here is everything you need to know and exactly what to do.
I will be honest — I have covered a lot of cybersecurity stories, and most follow a predictable pattern: phishing email, malicious link, malware installed, data stolen. Remote. Anonymous. Faceless. This one is different, and it genuinely unsettled me when I read it. A hacking group is now sending actual human beings to your office, in person, dressed as IT support workers, to plug USB drives into your computers and steal your data while your colleagues hold the door open for them.
This is not a thriller plot. Google’s Mandiant and Google Threat Intelligence Group confirmed it in a report published June 5, 2026. The FBI confirmed it independently in a Flash Alert issued May 26, 2026. Both organisations are treating it as a serious and active threat. Four named law firms have already had data published publicly after refusing to pay.
A cybercriminal gang called Silent Ransom Group (also known as Luna Moth, Chatty Spider, and UNC3753) has been targeting US law firms and businesses by posing as IT support staff. They first try to get remote access by phone or phishing email. If that fails, they physically send someone to the victim’s office to plug in a USB drive and steal data directly. The stolen data is then used to extort victims with threats of public exposure. Google and the FBI have both issued formal warnings as of June 2026. This group has been active since 2022, has data from over 38 firms published on its leak site, and total confirmed attacks exceed 100.
Who Is Silent Ransom Group?
Silent Ransom Group — also tracked under the names Luna Moth, Chatty Spider, and UNC3753 — is a financially motivated cybercriminal gang active since at least 2022. Security researchers assess the group has links to Russia and believe it emerged from the remnants of the Conti ransomware operation after Conti collapsed in 2022.
Despite the name, this group does not use ransomware in the traditional sense. They do not encrypt files and demand payment to unlock them. Their approach is pure data theft and extortion: steal your most sensitive data, then threaten to publish it or sell it unless you pay. It is arguably more dangerous than traditional ransomware because there is no decryption key to buy — once the data is out, it is out.
| Detail | Information |
|---|---|
| Group Names | Silent Ransom Group (SRG), Luna Moth, Chatty Spider, UNC3753 |
| Active Since | At least 2022 — linked to former Conti ransomware members |
| Suspected Origin | Russia (assessed by researchers — not officially confirmed) |
| Primary Targets | US law firms (since Spring 2023), plus insurance, finance, and healthcare |
| Attack Method | Data theft and extortion — no file encryption, no malware |
| New Tactic (Spring 2026) | In-person fake IT support visits to physically steal data via USB drive |
| Confirmed Leak Site Victims | 38+ firms — total attacks exceed 100 |
| Named Victims (2026) | Orrick Herrington & Sutcliffe, Jones Day, Wood Smith Henning & Berman, Ropers Majeski |
| Leak Site | business-data-leaks.com |
| FBI Flash Alert Date | May 26, 2026 |
| Google/Mandiant Report Date | June 5, 2026 |
The Real Victims — Named Law Firms
This is not abstract. Four named law firms have had data published by Silent Ransom Group in 2026 alone — all confirmed by multiple independent sources including DataBreaches.net, TechTimes, Crowdfund Insider, and the ABA Journal.
Orrick, Herrington & Sutcliffe — a firm with over 25 global offices and more than $1.5 billion in annual revenue — had data stolen in January 2026 and published publicly in February after ransom negotiations collapsed. Attackers gained access around January 20, maintained persistence for approximately one week, moved laterally across systems, and exfiltrated data before detection. Orrick subsequently contacted affected clients.
Jones Day confirmed via a phishing attack that an unauthorised third party accessed a limited number of files belonging to ten clients. The firm notified all affected clients. SRG published the data on March 30, 2026.
Wood Smith Henning & Berman, a California firm, had less than 4GB of data published in March 2026 after offering only $15,000 during negotiations — rejected by SRG, which demanded a six-figure sum. The leaked data included material from litigation related to a 2019 fatal helicopter accident.
Ropers Majeski was claimed as a victim by SRG as recently as May 6, 2026 — three weeks before the FBI Flash Alert.
The Attack — Step by Step
Understanding exactly how this attack works is the best defence against it. The sequence is consistent across all cases investigated by Google and the FBI.
An employee receives a call or phishing email appearing to come from their own company’s IT department. The message creates urgency — a security issue, a system migration, a compliance check. Historically SRG used fake subscription invoices to get people to call a cancellation number. The approach has since evolved into direct internal IT impersonation.
The attacker convinces the employee to allow a remote desktop session or download a screen-sharing tool. They use only legitimate applications — AnyDesk, Zoho Assist, Quick Assist, Splashtop, Syncro, RustDesk, and Atera — tools that antivirus software will not flag. The FBI explicitly states traditional antivirus is unlikely to catch this stage of the attack.
This is what separates Silent Ransom Group from virtually every other cybercriminal operation. If remote access is refused, the group physically sends an associate to the victim’s office. The person arrives posing as IT support, explains they need to plug in a USB drive to image the computer or create a backup, and connects directly to the machine. The FBI has confirmed multiple instances across different victim organisations.
Once inside — remotely or physically — attackers steal data using WinSCP and Rclone (sometimes renamed to avoid detection). Data is copied to USB drives or uploaded directly to Google Drive or Microsoft OneDrive. Target data includes contracts, Social Security numbers, financial records, tax documents, and client personal information. Desktops do not lock. No splash screen appears. Systems continue to function normally. Detection at this stage is extremely difficult.
The group sends ransom demands threatening to publish stolen files on business-data-leaks.com or sell them. In confirmed cases including Orrick, they have directly contacted the victim organisation’s own clients to apply additional pressure — a particularly aggressive escalation designed to maximise urgency and reputational damage.
“Mandiant has investigated various matters where adversaries planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks.”
Why Is This So Difficult to Detect?
Silent Ransom Group uses only legitimate, commercially available software throughout its operation. No malware is deployed. No files are encrypted. IT systems continue to function normally during and after the attack. The FBI says so explicitly in its Flash Alert — traditional antivirus products are unlikely to catch any part of this attack chain.
The threat is almost entirely social rather than technical. It exploits trust in authority figures and the human instinct to be helpful to someone who appears official. No firewall blocks a person walking through your front door in a branded polo shirt.
Imagine a burglar who, instead of picking your lock, knocks on your front door wearing a uniform, holds up a clipboard, says there is a gas leak in the building, and asks to check your meter. No lock is broken. No alarm is triggered. You let them in. That is Silent Ransom Group’s approach — and now in physical form too. The attack cannot be stopped by technology alone because the person holding the door open is a human being following their instinct to help someone who looks official.
Who Is Being Targeted and How Big Is the Problem?
Law firms are the primary and consistent target. Law firms hold exceptionally sensitive data — client contracts, personal identifying information, financial records, tax documents, and details of active legal proceedings. That data is both highly valuable and deeply embarrassing if published, making law firms ideal extortion targets: they have both the money to pay and the reputational motivation to do so quietly.
The scale is significant. Halcyon’s Ransomware Research Centre tracked 134 ransomware and data extortion incidents against law firms and legal services organisations in Q1 2026 alone — making legal the fourth most targeted industry globally, accounting for more than 6% of all attacks tracked in that period. Silent Ransom Group and the separate INC ransomware operation are identified as the primary drivers of that surge.
But law firms are not the only targets. Silent Ransom Group has also attacked organisations in insurance, finance, and healthcare. Any business that holds sensitive client data and has a recognisable IT department structure is potentially in scope. If your staff would instinctively help someone who introduced themselves as IT support, your organisation is vulnerable to this approach.
“We can confirm we have seen multiple instances of individuals impersonating IT support who have gained or attempted to gain physical in-person access to victim companies’ offices and/or devices as part of Silent Ransom Group’s scheme to exfiltrate data.”
What You Should Do Right Now
The good news is that this attack relies almost entirely on social engineering — clear policies and staff awareness can neutralise most of it before any technology comes into play.
- Verify before you comply. Any unannounced IT support visit or call should be verified by calling your actual IT department on a known number before granting any access. Do not use the number the caller provides.
- Never allow USB devices from unverified visitors. No legitimate IT team should ever need to plug an unknown USB device into your computer without prior written approval and a tracked work order.
- Train your staff specifically on this tactic. Most security awareness training covers phishing emails. Make sure it also covers social engineering by phone and in-person impersonation — the FBI has confirmed this is happening now, in 2026.
- Implement a visitor registration policy. Anyone arriving to perform IT work should be pre-registered, carry verifiable credentials, and be escorted at all times. No exceptions for people who seem helpful or urgent.
- Monitor remote access tool installations. If AnyDesk, Zoho Assist, Quick Assist, Splashtop, RustDesk, Syncro, or Atera appear on a machine outside a known IT deployment, treat it as a potential incident immediately.
- Watch for FBI-identified warning signs. Unauthorised remote access tool downloads; WinSCP or Rclone connections to external IPs; unauthorised USB connections; data exfiltration alerts to OneDrive or Google Drive; unidentified individuals claiming to be IT support; employees receiving unsolicited IT support calls.
- Report incidents to the FBI at ic3.gov. Preserve all evidence — ransom notes, phishing emails, communications, cryptocurrency wallet details, and any surveillance footage of in-person visitors.
Call back on a known number. Every single attack in this campaign depends on the victim trusting the caller’s identity. If your organisation has a standing rule that any IT support request — by phone, email, or in person — is verified by calling the real IT helpdesk on the number in your company directory before any access is granted, this attack fails at step one. That one policy costs nothing and stops this cold.
My Take — Mr Wangdoo
The thing that strikes me most is not the technical sophistication — there is not much. What is striking is the boldness. Sending a human being into an office building, in person, to physically steal data from a computer takes operational confidence that most cybercriminal groups simply do not have. This group does. They have been doing it repeatedly, across multiple confirmed cases, since at least Spring 2026.
Four named law firms — Orrick, Jones Day, Wood Smith Henning & Berman, Ropers Majeski — have all learned this the hard way in 2026. The real lesson here is that the weakest link in any security chain is a polite, helpful person who holds the door open for someone carrying a clipboard. Training people on that reality, specifically and repeatedly, is worth ten times what most organisations spend on endpoint security software.
If you run a law firm, an insurance company, a financial services business, or honestly any organisation where the words “IT support” would get someone through your front door with a USB drive — this needs to be on your staff training agenda this week, not next quarter.
Frequently Asked Questions
Is this threat real or has it been exaggerated?
It is real and confirmed by two independent authoritative sources. The FBI confirmed to TechCrunch that multiple instances of individuals impersonating IT support gaining physical access to victim offices have been verified. Google Mandiant independently investigated cases involving in-person access from January through May 2026. Named victims include Orrick Herrington & Sutcliffe, Jones Day, Wood Smith Henning & Berman, and Ropers Majeski. This is not hypothetical.
What are all the confirmed names for Silent Ransom Group?
The group is tracked under four confirmed aliases: Silent Ransom Group (SRG), Luna Moth, Chatty Spider, and UNC3753. All four names refer to the same threat actor and appear across FBI, Google/Mandiant, Help Net Security, and Infosecurity Magazine reporting.
Why are law firms the main target?
Law firms hold exceptionally sensitive data — client contracts, Social Security numbers, financial records, tax documents, and active legal proceedings. That data is both financially valuable and highly damaging if published, making law firms ideal extortion targets. They have both the money to pay and the reputational motivation to resolve incidents quietly. The FBI notes SRG has consistently targeted US-based law firms since Spring 2023, though attacks on insurance, finance, and healthcare are also confirmed.
Will antivirus software protect against this attack?
No — the FBI explicitly states in its May 26, 2026 Flash Alert that traditional antivirus products are unlikely to flag these attacks. The group uses only legitimate remote access tools such as AnyDesk, Zoho Assist, Quick Assist, Splashtop, Syncro, RustDesk, and Atera. These are trusted business applications that security software has no basis to block. The defence is human awareness and verification policies, not software.
What data does the group typically steal?
Confirmed stolen data includes client contracts, Social Security numbers, financial records, and tax documents. In the Orrick case, attackers maintained access for approximately one week and moved laterally across systems before exfiltrating. The group targets data that is both sensitive and embarrassing — maximising the victim’s motivation to pay rather than have it published publicly.
How do I report an incident to the FBI?
Report at ic3.gov. Preserve all available evidence including ransom notes, phishing emails, suspicious communications, cryptocurrency wallet information, and any surveillance footage from the period of the alleged visit. Do not delete anything before speaking to law enforcement.
Is this group only targeting US businesses?
The FBI warnings and Google’s report focus specifically on US-based organisations and US law firms. However, Silent Ransom Group is a financially motivated threat actor with no ideological constraints on geography. Organisations outside the US holding sensitive legal, financial, or medical data should treat this as relevant to their threat model.
- TechCrunch — Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person (June 5, 2026)
- FBI IC3 — FBI Flash Alert: Silent Ransom Group Impersonating IT Personnel (May 26, 2026)
- Google / Mandiant — Targeted Campaign Against US Law Firms — Google Threat Intelligence Group (June 5, 2026)
- Help Net Security — Hackers are knocking on office doors pretending to be IT staff (May 27, 2026)
- DataBreaches.net — Silent Ransom Group leaked Orrick, Herrington & Sutcliffe (April 2026)
- Infosecurity Magazine — Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems
- TechTimes / Halcyon — Silent Ransom Group Sends Operatives Into Law Firm Offices: 38 Firms Already Leaked
- PYMNTS.com — Google Warns That Fake IT Workers Are Stealing Financial Data (June 5, 2026)