Threats · 110 days ago

SRG Adds Office Visits to Its Extortion Playbook

SRG has moved the theft phase off the network and into the building. If its help-desk impersonation fails, the group now sends someone to the office to get local access and copy data directly, which makes remote-access controls and antivirus miss the real break.

The FBI says the campaign still starts with phone calls or phishing emails that push employees toward a fake IT support session. When that does not work, SRG sends an impostor in person to plug in a USB or external drive and take files from the workstation, then uses the stolen data for extortion against U.S. law firms and similar targets in finance and healthcare.

That shift expands the blast radius beyond email filtering and remote-desktop policy. Once an attacker is physically in front of a machine, the trust problem becomes the security problem, and the trail can be thin enough that the theft is discovered only when the extortion demand arrives.

Timeline

Sources

7 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories