Threats · 110 days ago
SRG has moved the theft phase off the network and into the building. If its help-desk impersonation fails, the group now sends someone to the office to get local access and copy data directly, which makes remote-access controls and antivirus miss the real break.
The FBI says the campaign still starts with phone calls or phishing emails that push employees toward a fake IT support session. When that does not work, SRG sends an impostor in person to plug in a USB or external drive and take files from the workstation, then uses the stolen data for extortion against U.S. law firms and similar targets in finance and healthcare.
That shift expands the blast radius beyond email filtering and remote-desktop policy. Once an attacker is physically in front of a machine, the trust problem becomes the security problem, and the trail can be thin enough that the theft is discovered only when the extortion demand arrives.
7 sources covering this story
Ransomware Actors Show Up In Person to Steal Law Firm Data
The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and social-engineering its way into servers and databases.
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
Silent Ransom Group isn’t prolific, but it's demonstrated a knack for attacking the legal services sector with an extraordinary dual use of social engineering and in-person visits to victims’ workstations.
Extortion crews are visiting law firms pretending to be tech support, FBI warns
Cybercriminals still allowed to walk into office blocks and convince staff to let them plug in their own thumb drives
Hackers are knocking on office doors pretending to be IT staff - Help Net Security
The Silent Ransom Group is targeting law firms through social engineering attacks involving phishing emails and in-person visits.
The Record from Recorded Future
FBI warns extortion hackers are visiting US law firms to steal data
In a public advisory issued Tuesday the FBI said a hacking group has targeted law firms using social engineering schemes to gain remote access to corporate systems and exfiltrate data.
FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data
The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.
FBI warns of in-person data theft attacks from extortion gang
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
Part of the PlainSec briefing for 2026-05-27