SRG Moves Its Scam From Phones to Office Doors

The weak point is no longer just remote support. If a phone scam fails, SRG now sends someone to the office to create the access in person, which turns help-desk trust and physical reception into the entry point. The FBI says the group has shifted from callback phishing and remote desktop abuse to posing as IT staff on calls, then sending an operative to insert a USB or external drive when the remote attempt fails. That lets SRG copy data straight off the machine, with little malware noise and few artifacts left behind. That expands the blast radius beyond email controls and remote-access policy. For law firms, and for finance and healthcare teams with similar support workflows, the risk now runs through front-desk checks, workstation access, and device handling.

Part of the PlainSec briefing for 2026-05-27

Sources