In May 2026, the FBI issued a flash alert warning US law firms about a threat actor that has evolved well beyond conventional phishing. Silent Ransom Group — also tracked as Luna Moth, Chatty Spider, and UNC3753 — has been targeting American legal practices since 2023. What changed this year is the method. When a phone call fails to produce access, they send someone in.
The attack follows a structured pattern. SRG operatives phone the target organisation, impersonating its own internal IT department. They tell the employee that their device has been affected by a phishing campaign and that IT needs to image it or take a backup. The employee is directed to open a remote desktop session. In most cases, that is enough. The attackers gain remote access, escalate privileges minimally, and use legitimate tools — WinSCP, Rclone, AnyDesk — to exfiltrate data quietly, without encryption, without triggering traditional antivirus software.
When the phone call fails — when an employee is sceptical, refuses to comply, or simply hangs up — Silent Ransom Group does not move on. They send a person. A physical operative arrives at the law firm’s office, identifies themselves as IT support, and asks to connect a storage device to the employee’s workstation. The same pretext: imaging the device, creating a backup. If the operative gains physical access, data is exfiltrated directly to an external drive. No network detection. No authentication event. No log entry that triggers an alert.
The FBI’s May 2026 alert confirmed that this tactic has been operational since at least April 2025, and has already resulted in 38 US law firms having data published on extortion leak sites. One confirmed ransom demand in May 2026 reached $20 million. The sensitivity of legal data — privileged client communications, case files, financial records — makes law firms a high-yield target for exactly this kind of extortion.
The defences that failed here were not weak by conventional standards. Antivirus software was present. MFA was in place on many accounts. The building had a reception desk. None of it mattered, because the attack did not break any of these controls. It bypassed them by impersonating the person who legitimately operates them.
GoFirm addresses this at two points. The remote desktop session is an execution event. Before any employee can open remote access to their machine in response to an IT request, a confirmation request goes to the named IT authority on their registered device — not to the person who called claiming to be IT. The physical operative faces the same control. Connecting an external storage device to a workstation containing sensitive data is a configurable gate. The request requires confirmed human authority from a named administrator before it can proceed.
A phone call from an attacker, however convincing, cannot produce that confirmation. An operative physically present in a law firm’s lobby cannot produce it either. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. FBI / IC3, Flash Alert: Silent Ransom Group Targeting Law Firms, 26 May 2026. https://www.ic3.gov/CSA/2026/260526.pdf
2. Halcyon Ransomware Research Center, An Old Tactic Returns: Silent Ransom Group’s Active Use of Physical Intrusion Against U.S. Law Firms, 11 June 2026. https://www.halcyon.ai/ransomware-alerts/an-old-tactic-returns-silent-ransom-groups-active-use-of-physical-intrusion-against-u-s-law-firms
3. Infosecurity Magazine, Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems, 29 May 2026. https://www.infosecurity-magazine.com/news/silent-ransom-group-it/
4. Dark Reading, Silent Ransom Group Hits US Law Firms in Escalating Attacks. https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks
