Monday, August 3, 2026

Policy & Regulation

Silent Ransom Group targets law firms with fake IT workers

The Silent Ransom Group is targeting law firms by sometimes sending fake IT workers to offices to steal data, according to reports from Google and the FBI.

Silent Ransom Group targets law firms with fake IT workers

On Friday, Google’s cybersecurity teams Mandiant and Google Threat Intelligence Group published a new report warning that a ransomware gang has escalated its attacks on law firms. According to Google and the FBI (the US federal law enforcement agency), the cybercriminal gang known as the Silent Ransom Group is sometimes sending fake IT workers in person to the victims’ offices. The group attempted to steal victims’ information using physical, in-person access in attacks from January through May of this year, targeting dozens of victims. Last month, the FBI published an alert warning that the group targets law firms with social engineering and phishing attacks pretending to be IT support employees.

The hackers use a mix of digital and physical tactics to execute their schemes. According to Google’s researchers, the group relies on phishing emails, follow-up phone calls, and social engineering to trick employees. Google’s researchers reported that the callers use various verbal instructions to guide target behavior, building trust under the guise of addressing a security issue or helping with a corporate data migration project to direct the target to join a screen-sharing session. In some cases, however, the group takes the intrusion physical. Once inside an office, the imposters connect to employees’ computers to steal data directly using USB drives or remote access tools. Rather than encrypting systems like traditional ransomware operations, the gang relies on pure extortion. It operates its own leak site where it threatens to publish the stolen data if the victim does not pay. In emails sent directly to victims, the hackers threatened to notify employees, partners, and customers, and then publish the data if there was no agreement or if their demands were ignored.

This hybrid approach of combining digital social engineering with physical, in-person deception represents a notable shift for cybercriminals. An FBI spokesperson confirmed the physical aspect of the threat, stating: “We can confirm we have seen multiple instances of individuals impersonating IT support who have gained or attempted to gain physical in-person access to victim companies’ offices and/or devices as part of Silent Ransom Group’s scheme to exfiltrate data.” While physical breaches are rare compared to remote hacks, they are not entirely unprecedented. Charles Carmakal, the chief technology officer of Mandiant (Google’s cybersecurity firm), noted that the firm has investigated various matters where adversaries planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks.

Why it matters

This shift toward physical, in-person intrusions marks a significant escalation in ransomware tactics, allowing attackers to bypass traditional encryption-based security models by stealing data directly.