Cyber & AI intelligence
Wasteland.
Briefs indexed3097
Issues31
Published Mondays07:30 CT
█ Ransomware SILENT-RANSOM-GROU 2026-10-09

Silent Ransom Group: Leaked Chats Claim $207M Extorted Without Encryption

"Someone has leaked the internal chat archive of Silent Ransom Group (SRG), the Russia-based extortion crew also tracked as Luna Moth and Chatty Spider. The chats appear to show the group collected about $207 million…"

Someone has leaked the internal chat archive of Silent Ransom Group (SRG), the Russia-based extortion crew also tracked as Luna Moth and Chatty Spider. The chats appear to show the group collected about $207 million from 27 victim firms in under six months, and it never encrypted a single system. The figure comes from what the group itself recorded. SRG's internal deal board marks 27 firms as paid between April 3 and September 24, 2026. DataBreaches.net, The Register, Recorded Future News and blockchain analysts all report the total at roughly $207 million. Wire Observer gives it more precisely as $206.95 million. No independent party has verified that number. Crystal Intelligence says on-chain evidence "supports the scale but not the exact figures." Chainalysis has matched some of the leaked wallet addresses to extortion payments it already knew SRG had collected, but says it cannot "speak to the totality of claims" in the archive. One OTHER-tier outlet (gblock.app) reports that SRG denies being breached.

What Happened

DataBreaches.net first received the leak through researcher Tammy Harper. It was published as an .onion site containing 5,692 chat messages taken from two SRG servers (slplsskdj2836v2jjsx.com and aim6umein3kee.com). The messages run from August 27, 2025 to September 29, 2026. Harper has also posted another presentation of the data at ctifiles[.]com. Recorded Future News says the archive went up in early October through a bespoke .onion site, posted by an unidentified source who gave no motive. gblock.app reports the archive was titled "The Luna Moth Files."

Wire Observer (OTHER) has a different account. It says a whistleblower uploaded the logs to an encrypted drop site and that law enforcement is reviewing them. No outlet-tier source confirms either claim, so who leaked the archive, and why, remains unknown. DataBreaches.net compares the dump to the 2022 Conti leaks. That comparison fits, since SRG is widely described as a Conti offshoot.

According to the sources that reviewed the archive, the chats cover:

The sources disagree on whether victims are named. Wire Observer says the chats do not name the companies. Recorded Future News says some of the organizations named in the archive have not publicly acknowledged a breach. This brief gives more weight to Recorded Future News, an established outlet that reviewed the material directly.

What Was Taken

The leak is the group's own data rather than a single victim's breach, so no single dataset was stolen here. What the chats document is SRG's business model: it steals data from professional services firms, mostly law firms, and threatens to leak it.

Several recent SRG victim claims fill in the picture, though none are confirmed:

Why It Matters

Earlier ransomware models depended on encryption. SRG's leaked figures suggest that encryption isn't needed to make large sums from extortion. Taking the data and applying legal and reputational pressure appears to be enough, especially against law firms, whose business rests on confidentiality. Wire Observer calls this "double extortion," but the label doesn't really apply. Double extortion means encryption plus a leak threat, and SRG skips the encryption entirely. Defenses built around detecting encryption, such as canary files, mass file-rename alerts and backup restore drills, do nothing against this model.

According to DataBreaches.net, SRG has successfully attacked more than 100 law firms, and no victim has ever claimed SRG leaked fabricated data. That record gives its threats weight in negotiations. The Hogan Lovells Cadwalader case also shows that refusing to pay can bring a second intrusion.

The physical side is the most unusual part. The FBI warned in May 2026 that people posing as IT staff were entering law offices and copying files to USB drives. gblock.app reports that the leaked chats show these "agents" being recruited through Telegram job ads. A Russian extortion crew with paid people on the ground in the US is a hybrid insider/physical threat that most law firm security programs are not built to handle.

The Attack Technique

The sources agree on a layered approach to getting in:

  1. Callback phishing: The FBI's account, summarized by gblock.app, says intrusions start with an email, usually a fake subscription or invoice notice, that tells the target to call a phone number. That puts the victim on the phone with SRG operators.
  2. Fake IT support calls: Operators pretend to be the help desk and talk employees into installing legitimate remote-access tools or granting a remote session. After that, they exfiltrate data with standard file-transfer utilities.
  3. Physical intrusion as the fallback: If an employee refuses remote access, gblock.app reports, citing the FBI, that SRG sends an "agent" posing as IT personnel to the office to copy files onto a USB drive. Crystal Intelligence also notes that SRG has recently added in-person office visits.
  4. Hands-on access to separate infrastructure: In the Hogan Lovells Cadwalader case, SRG says it used "a new set of tools" to get into legacy systems that had their own firewall and authorization controls. It did not say what those tools were.

None of the sources describe malware deployment, encryption, or destructive activity. The intrusions are mainly social engineering followed by data theft using legitimate tools.

What Organizations Should Do

  1. Lock down IT support identity checks. Publish to all staff that IT will never cold-call asking for remote access, and require callbacks to a known internal number or ticket verification before any remote session. Train staff to treat invoice and subscription emails that include a phone number as suspicious.
  2. Allowlist remote monitoring and management (RMM) tools. Block unapproved remote-access software (AnyConnect-style lookalikes, Zoho Assist, AnyDesk, ScreenConnect and similar) at the endpoint. Alert on any new RMM install or first-time remote session to a user workstation.
  3. Verify physical visitors. Require advance tickets and escort for any "IT technician" coming on site. Confirm their identity with your actual IT team or managed service provider before they touch a device, and brief reception and office managers on the FBI's May 2026 warning.
  4. Control removable media. Block or log USB mass-storage writes on endpoints that handle client matters, and alert on large copies to removable drives.
  5. Watch for exfiltration, not encryption. Monitor for unusual outbound volume, use of cloud-storage and file-transfer utilities like rclone or WinSCP, and bulk access to document management systems. Assume legacy and merged-firm infrastructure is in scope.
  6. Plan for no-encryption extortion. Your incident response playbook should cover pure data-theft demands, including legal privilege handling, client notification, and the risk of a second attack if you decline to pay. Hunt against SRG tradecraft now rather than waiting for a leak-site listing.

Sources: Silent Ransom Group’s Chat Leaks Reveal $207 Million Data‑Extortion... | Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked... | Can you really make more than $200M in six months without encryptin... | Money trail backs leaked chats from extortion crew that walks ... | Leaked chats show Russian extortion gang sending 'agents ... | Silent Ransom Group Leak Shows Agents Sent Into US Law Firms | SILENTRANSOMGROUP Leak-Site Activity: 3 New Listings — Legal & Prof... | Andersen Group Inc. Listed on LeakedData (Silent Ransom ...