The FBI’s warning about Silent Ransom Group shows how data-theft extortion is moving beyond traditional malware and ransomware playbooks. The group, also known as Luna Moth, Chatty Spider, and UNC3753, is reportedly targeting U.S. law firms with social engineering calls and phishing emails, then even sending someone in person posing as IT support to insert a storage device and steal sensitive data.

This is especially concerning for law firms because they hold highly sensitive client information, contracts, case files, financial records, M&A material, litigation data, and privileged communications. In this model, attackers do not need to encrypt systems to create pressure. They steal the data quietly, then use the threat of exposure as the ransom weapon. Because apparently ransomware without encryption is now the “minimalist” criminal trend. 

Organizations should treat IT support impersonation as a serious physical and cyber risk. Employees should be trained to verify any unexpected IT request through official internal channels, especially if someone asks to connect remotely, install tools, plug in storage media, or visit the office for “support.” Reception teams, office admins, and security guards also need clear procedures for validating third-party IT visitors. 

Security teams should restrict USB storage, enforce endpoint controls, monitor unusual data transfers, audit remote access tools, and review logs for suspicious activity after any unexpected support contact. The bigger lesson is simple: social engineering is no longer just email. It can be phone calls, fake helpdesk workflows, remote-access sessions, and now physical visits. Attackers follow trust, and trust without verification is just a breach waiting politely at reception.


The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. [...]

Source: FBI warns of in-person data theft attacks from extortion gang via Bleeping Computer — published 27 May 2026.