Oct 09, 2026 · 9 min read
Silent Ransom Group Leak Shows Agents Sent Into US Law Firms
A leaked archive of 5,692 chat messages attributed to the Silent Ransom Group shows a Russian extortion crew recruiting walk in operatives through Telegram job ads and claiming about $207 million from 27 firms in six months. Chainalysis has matched some of the wallets to known extortions. The group denies the leak is real.
Somebody walked into a New York law firm's office and copied files onto a flash drive. The firm knew it. In a negotiation preserved in the leaked chats, a representative told the extortionists that its executives had authorized $1 million to settle, but wanted proof that every digital and physical copy would be destroyed, according to Recorded Future News.
That exchange is one entry in a cache that security researchers are calling the Silent Ransom Group leak. It turns the FBI's warnings about impostor IT technicians into an org chart, a recruiting funnel and a revenue board. It also sits on top of something less cinematic. By the FBI's account, the office visit is SRG's backup plan, and the first contact is an email or a phone call.
Key Takeaways
- A leaked archive of 5,692 Silent Ransom Group chat messages, covering August 27, 2025 to September 29, 2026, appeared on a .onion site in early October 2026 under the title The Luna Moth Files.
- Chainalysis said certain leaked wallet addresses sit downstream of millions of dollars SRG extorted from victims, but it could not vouch for every claim, and SRG told DataBreaches.net it denies being breached.
- The chats describe agents recruited through Telegram job ads to enter U.S. law firm offices, and one New York firm said its executives had authorized $1 million after someone copied files onto a flash drive in its office.
- SRG's internal deal board marks 27 firms as gold, meaning paid, for about $207 million between April and September 2026, a total no outside party has verified.
- The FBI says SRG intrusions begin with callback phishing emails or fake IT support calls, and the office visit is the fallback when an employee refuses remote access.
What Is in the Silent Ransom Group Leak?
The Silent Ransom Group leak is a dump of internal chats from the extortion crew also tracked as Luna Moth, Chatty Spider and UNC3753, posted by an unidentified source who gave no motive. DataBreaches.net counts 5,692 messages pulled from two servers between August 27, 2025 and September 29, 2026. Crystal Intelligence, which also analyzed the export, says most are in Russian.
The Record describes a mix of apparent extortion records and violent fantasy. About 50 organizations appear, mostly law firms. Several have disclosed cyber incidents this year; others have said nothing. We are not naming firms that have not confirmed an attack.
One caveat sits on top of everything else. On October 8, DataBreaches.net updated its report: SRG agreed to an interview about the Luna Moth Files but "denies that the group has been breached or leaked."
How Much of the Leak Has Been Verified?
The money trail has been partly verified; the most extreme plans have not. Chainalysis told The Register that "certain leaked SRG addresses sit downstream of millions of dollars in ransomware payments that SRG has extorted from victims," while adding that it cannot "speak to the totality of claims." One member's wallet named in the chats, Chainalysis said, is funded entirely by a victim payment of more than $10 million that it was already tracking before the leak.
Crystal Intelligence, another blockchain analytics firm, traced the leaked payout wallets upstream to a collection wallet that received about 2,675 bitcoin over its lifetime. DataBreaches.net checked the chats against material SRG had sent it earlier about one victim, and the name, email address, date and $4 million offer all matched.
What remains unverified: talk of kidnapping executives or relatives, a sexual blackmail scheme, photographing a target's school age child, and a channel created in May about recruiting U.S. sailors near naval bases. The Record found nothing in the archive showing any of it was carried out.
How Did SRG Recruit Agents to Walk Into Law Firms?
SRG recruited its agents through paid Telegram ads dressed up as ordinary jobs. The Record lists nightclub promotion, courier work and security; Crystal's analysis, cited by The Register, found listings promising "$300+ per night" for "nightclub promoters." The ads appear to target Russian speakers, The Record reports.
It was a messy pipeline. A roster lists agents by numbered code and city, including a 17 year old marked ready to work. In February the group's apparent leader put the usable rate at one in 10 and called it the operation's "conversion." Some recruits took the money and vanished; others backed out at the office door.
The ideas for getting past reception ran from plausible to theatrical:
- A pizza delivery ruse: get through reception with insulated bags, then pose as IT in the main office.
- Custom masks modeled on real lawyers, and smart glasses for an agent posing as a client.
- A $3,200 ultraviolet printer and holographic materials for ID cards, plus payments to forgers, one in New York.
Nothing shows the pizza or mask ideas were used. The core tactic is not in doubt. The FBI documented it in a May 23, 2025 Private Industry Notification, which says that as of April 2025 SRG "sent an individual in person to access the computer and insert a storage device." We covered the follow up warning in the FBI's May 2026 advisory on SRG walking into law firm offices.
Inside the Sales Pipeline: Chat, Offer, Contract, Gold
SRG tracked victims like a sales team tracks leads. Entries moved from "chat" to "offer," "contract" and "gold." In one negotiation a $100,000 opening offer was mocked as "missing a zero," then climbed through $500,000, $1.5 million, $2.25 million, $3 million and $3.5 million to a $6 million contract.
DataBreaches.net totaled the 27 gold entries at $206,950,000, with a median of $6 million and a high of $30 million. Nine of the 27 disclosed breaches in 2026 that line up with the dates in the chats. None has confirmed paying.
Put that claim next to the industry total. Chainalysis' 2026 ransomware report counted $820 million in on chain ransomware payments for all of 2025, as BleepingComputer reported. If SRG's own figure is accurate, one crew that never encrypts a file took the equivalent of a quarter of that year's global haul in under six months. The prices also rose. In May 2025 EclecticIQ put SRG's demands at one to eight million dollars; the leaked median sits near the top of that range, and the largest claimed payment is almost four times its ceiling.
Why Email Users Should Care: The Attack Still Starts in the Inbox
The agent is the fallback, not the opening move. The FBI's FLASH-20260526-01, dated May 26, 2026, says SRG actors "either directly call or send phishing emails to urge employees to call the SRG actor posing as IT support," and only "if that attempt fails" sends someone to the building. Its ATT&CK table lists initial access as "Callback phishing emails using invoice, billing, subscription, or IT-themed lures."
The lure in a callback phishing email is a phone number, not a malicious link. In 2022, BleepingComputer reported that Luna Moth sent fake Zoho, MasterClass and Duolingo renewal notices from Gmail accounts, each with an invoice attached and 24 hours to pay or call. By March 2025, EclecticIQ found, the group had registered at least 37 typosquatted help desk domains following patterns such as [company_name]-helpdesk.com.
Email also bookends the attack. Per the FBI, the ransom demand arrives as an email, and SRG pressures victims by emailing or calling their clients to say their data was stolen. For a law firm, that puts the extortion pitch in its clients' inboxes. The same call me now pattern drives the ATHR callback phishing kit.
The timeline is the uncomfortable part. The FBI's 2026 alert was not its first word on office visits. The bureau described the tactic in May 2025, the leaked chats begin three months later, and they show the group still recruiting and managing agents in 2026. A public FBI warning did not end the tactic.
What Should Law Firms Do Now?
Break the chain at the email and at the front desk, because the FBI says traditional antivirus is "unlikely to flag the intrusion." Steps drawn from the 2026 FLASH:
- Treat call this number emails as phishing. Subscription renewals, invoices or IT tickets that push you to phone a number are SRG's documented lure. Look up the vendor or help desk number yourself.
- Publish how IT contacts staff. The FBI recommends written policies on "when and how IT support will communicate and authenticate themselves." Unscheduled callers fail by default, the same rule that stops fake IT support calls over Microsoft Teams.
- Verify every visitor. The FBI's first recommendation is to check credentials of everyone entering company spaces, "including obtaining copies of each visitor's ID card." Reception should confirm with a named internal IT contact before anyone touches a workstation.
- Block unapproved remote tools. The FBI names Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop and Atera among the remote tools whose unauthorized download is an SRG indicator.
- Lock down USB storage. Disable external drive installation on machines with confidential data, and alert on WinSCP or Rclone connections to external addresses.
- Require phishing resistant MFA for as many services as possible, and keep the original callback email if you are targeted. The FBI asks victims for it.
The Compliance Angle: What a $1 Million Payment Buys
Very little that can be proven. The New York firm asked for proof of deletion and cited evidence that LockBit kept data from victims who paid. That evidence is real: after the February 2024 takedown, law enforcement found LockBit was holding data it had promised to delete.
Payment carries legal risk too. Treasury's OFAC advisory on ransomware payments says there is "no guarantee that companies will regain access to their data or be free from further attacks," and that OFAC may impose civil penalties on a strict liability basis. Nothing in the leak shows SRG is sanctioned. But one cash out channel in the chats, a Bitcoin to Zelle desk, uses a Telegram handle that Crystal's database links to an exchange it describes as unlicensed and sanctions flagged.
The leak also hands defenders a lead. Crystal found that many smaller payments, including wages to agents and fees to forgers, went straight to regulated exchanges that verify identities, which it calls "the network's weakest point."
Looking Ahead: Sleepless Threat
The chats end with the group discussing a relaunch under the brand Sleepless Threat. "The ultimate goal is to become a social movement or a cult," a senior member wrote in April, according to The Record. A new name changes nothing about detection. The FBI's indicators describe behavior, not branding: an unscheduled visitor claiming to be IT, or a remote access tool nobody approved. Those signals hold under whatever name the group uses next.