# FBI Warns of Escalating Physical Data Theft Attacks by Silent Ransom Group Against U.S. Law Firms


The Federal Bureau of Investigation issued an urgent warning on Tuesday alerting organizations—particularly law firms—to an escalating threat from the Silent Ransom Group (SRG), a cybercriminal organization that has shifted tactics to include in-person physical attacks on corporate networks. The gang, also known as Luna Moth, Chatty Spider, and UNC3753, is now combining social engineering with direct facility access to steal sensitive data, marking a dangerous evolution in extortion campaigns targeting the legal and financial sectors.


## The Threat: A Hybrid Attack Model


SRG's current attack methodology represents a dangerous hybrid of cyber and physical security exploitation. The group operates using a two-stage approach: if initial remote access attempts fail, threat actors physically visit victim locations to extract data manually.


The attack sequence typically unfolds as follows:


1. Initial Contact: SRG actors contact employees via phone or phishing emails, impersonating IT support staff from the victim's own organization

2. Social Engineering: They convince targets to grant remote desktop access under the guise of routine IT maintenance or security updates

3. Physical Escalation: If employees refuse or detect the ruse, SRG dispatches threat actors to the victim's physical location

4. Data Exfiltration: The on-site attackers insert USB drives or external hard drives into company computers, directly copying sensitive files

5. Extortion: Stolen data is used as leverage, with threat actors demanding ransom payments while threatening to sell or publish the information


According to the FBI alert, organizations should watch for specific red flags: unauthorized individuals claiming to be IT support, unsolicited requests for remote access, and physical intrusions by unidentified personnel attempting computer access.


## Background and Context: From Conti to Independent Operations


Silent Ransom Group did not emerge in isolation. The organization has deep roots in the Russian-speaking cybercriminal ecosystem and a documented history of high-impact operations.


Timeline of Evolution:


  • 2022: SRG confirmed active, targeting U.S. organizations
  • Early 2023: Formal shift in focus toward U.S. law firms and financial institutions
  • 2022-2025: Linked to BazarCall campaigns that provided initial network access for Conti and Ryuk ransomware operators
  • March 2022: After the Conti ransomware-as-a-service (RaaS) operation shut down, SRG operators separated and formalized as an independent extortion gang
  • May 2025: FBI issued a private industry notification warning of callback phishing and social engineering attacks lasting over two years
  • May 2026: Current alert escalates threat level due to confirmed in-person attack activity

  • Law firms represent high-value targets for SRG. These organizations maintain extensive repositories of confidential client data, intellectual property, litigation strategies, mergers and acquisitions details, and financial information. A single successful breach can expose privileged attorney-client communications and sensitive business intelligence worth millions in ransom demands.


    ## Technical Details: Social Engineering and Physical Bypass


    What makes SRG's approach particularly effective is its exploitation of the trust gap between employees and IT support functions. The group has developed sophisticated impersonation tactics:


    Domain Impersonation Techniques:

  • Registration of typosquatted domains designed to mimic IT helpdesk and support portals
  • Use of realistic email addresses and phone numbers that closely match legitimate IT department contacts
  • Crafting phishing emails that reference internal systems and processes (likely obtained from prior reconnaissance)

  • Remote Access Tools:

  • Leverage of legitimate remote desktop applications that organizations already use and trust
  • Minimization of suspicious activity indicators by using standard corporate communication channels
  • Extraction of data through normal file transfer mechanisms, reducing detection likelihood

  • Physical Attack Methodology:

  • Direct insertion of external storage devices bypasses network-based data loss prevention (DLP) controls
  • Physical access circumvents endpoint detection and response (EDR) solutions that monitor network traffic
  • Attackers require minimal technical sophistication once physical access is granted—often simply copying entire directories to external media

  • The in-person component represents a critical vulnerability: it exploits the assumption that physical security and network security operate independently, when in reality a breach of one directly compromises the other.


    ## Implications for Organizations


    The threat landscape for sensitive data now encompasses both cyber and physical threat vectors simultaneously. Organizations cannot treat network security and physical security as separate operational domains.


    High-Risk Sectors:

  • Law firms (primary current target)
  • Financial services institutions
  • Corporate headquarters housing legal and strategy departments
  • Consulting firms managing client confidential information
  • Healthcare organizations (medical records and patient data)

  • Cascading Damage:


    Beyond the immediate financial impact of ransom demands, law firms face compounded risks:

  • Client notification obligations under state bar associations and data breach notification laws
  • Reputational damage that undermines client trust and retention
  • Regulatory scrutiny from state bar authorities and potential disciplinary action
  • Litigation exposure from clients whose privileged communications were compromised
  • Professional liability claims from clients harmed by breach of confidentiality

  • ## Recommendations: Layered Defense Strategy


    Organizations targeted by SRG should implement comprehensive defensive measures across physical, administrative, and technical domains:


    ### Physical Security Enhancements

  • Implement badge access systems restricting IT support to authorized personnel with verified credentials
  • Establish visitor verification protocols requiring photo ID and callback to employee departments before granting access
  • Deploy surveillance in server rooms, network closets, and sensitive areas
  • Restrict USB port access through hardware-level controls, disabling USB ports on executive and sensitive-access workstations

  • ### Administrative Controls

  • Establish verified communication protocols for IT support—employees should hang up and call back IT through official numbers from the company directory
  • Create IT support policies prohibiting unsolicited remote access requests
  • Implement multi-factor authentication for all network access, including remote desktop sessions
  • Conduct security awareness training specifically targeting social engineering and IT impersonation attacks
  • Develop incident response plans for suspected in-person attacks, including immediate law enforcement notification

  • ### Technical Defenses

  • Deploy endpoint detection and response (EDR) tools that alert on suspicious file copy operations
  • Implement data loss prevention (DLP) solutions that monitor for large data transfers to external media
  • Enable USB device logging to track all external storage connections
  • Segment networks so that data exfiltration from one compromised workstation does not expose enterprise-wide systems
  • Monitor for suspicious domain registrations mimicking your organization (typosquatting detection services)

  • ### Detection and Response

  • Monitor for phishing emails impersonating IT support with domain analysis and authentication checks
  • Log and review all remote access sessions for unusual activity, timing, or data access patterns
  • Establish baseline activity for network access tools to identify anomalous usage
  • Create escalation procedures for employees reporting suspicious IT contacts

  • ## Recommendations: Specific to Law Firms


    Law firms should consider industry-specific hardening:

  • Client notification protocols for breaches involving privileged communications
  • Coordination with bar association ethics committees on breach response
  • Enhanced monitoring of access to client files, particularly in litigation and M&A matters
  • Third-party security assessments focusing on physical and social engineering vectors

  • ---


    ## HackWire Analysis


    The escalation from remote social engineering to in-person data theft represents a critical inflection point in extortion gang operations. It signals two things: desperation and sophistication. SRG has learned that technical defenses—endpoint detection, multi-factor authentication, network segmentation—are increasingly difficult to overcome purely through cyber means. By shifting to physical attacks, they bypass layers of digital security infrastructure entirely.


    The targeting of law firms is particularly significant because these organizations operate under a different risk calculus than most corporate entities. Confidentiality obligations and attorney-client privilege create legal liability that extends far beyond the immediate breach. A stolen client file isn't just lost data; it's a potential violation of professional ethics rules. SRG understands this asymmetry—they're not just demanding ransom; they're threatening legal and professional destruction. This makes law firms far more likely to negotiate quickly and quietly, a pressure point the gang is actively exploiting.


    What should concern defenders most is that the in-person attack vector operates at the intersection of physical security and employee trust. A credential that works for one bypasses the other. The FBI's specific mention of "unidentified individuals claiming to be IT support" suggests SRG is fielding local operatives with enough knowledge to appear credible to office staff. This requires either recruitment of insiders or coordination with local accomplices—a maturation of the operation that indicates stability and resource commitment.


    For organizations that assume their physical security is adequate, this alert is a wake-up call: possession of a USB drive and five minutes of network access is often sufficient to extract thousands of confidential files. The gap between "technically connected" and "successfully exfiltrated" is far narrower than many security teams realize.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)