Someone has leaked the internal chat archive of Silent Ransom Group (SRG), the Russia-based extortion crew also tracked as Luna Moth and Chatty Spider. The chats appear to show the group collected about $207 million from 27 victim firms in under six months, and it never encrypted a single system. The figure comes from what the group itself recorded. SRG's internal deal board marks 27 firms as paid between April 3 and September 24, 2026. DataBreaches.net, The Register, Recorded Future News and blockchain analysts all report the total at roughly $207 million. Wire Observer gives it more precisely as $206.95 million. No independent party has verified that number. Crystal Intelligence says on-chain evidence "supports the scale but not the exact figures." Chainalysis has matched some of the leaked wallet addresses to extortion payments it already knew SRG had collected, but says it cannot "speak to the totality of claims" in the archive. One OTHER-tier outlet (gblock.app) reports that SRG denies being breached.
What Happened
DataBreaches.net first received the leak through researcher Tammy Harper. It was published as an .onion site containing 5,692 chat messages taken from two SRG servers (slplsskdj2836v2jjsx.com and aim6umein3kee.com). The messages run from August 27, 2025 to September 29, 2026. Harper has also posted another presentation of the data at ctifiles[.]com. Recorded Future News says the archive went up in early October through a bespoke .onion site, posted by an unidentified source who gave no motive. gblock.app reports the archive was titled "The Luna Moth Files."
Wire Observer (OTHER) has a different account. It says a whistleblower uploaded the logs to an encrypted drop site and that law enforcement is reviewing them. No outlet-tier source confirms either claim, so who leaked the archive, and why, remains unknown. DataBreaches.net compares the dump to the 2022 Conti leaks. That comparison fits, since SRG is widely described as a Conti offshoot.
According to the sources that reviewed the archive, the chats cover:
- Victim payments and multimillion-dollar negotiations, tracked on an internal "deal board" that marks paid firms as "gold."
- Ways to get into future victims and ideas for approaching them.
- Direction of US-based operatives the group calls "agents."
- Personal and operational chatter, including a member buying an apartment in Moscow and discussions of guns and drones.
- Ideas Recorded Future News describes as kidnapping business executives and recruiting military personnel to spy on submarine-based nuclear forces. The outlet says it could not verify whether any of these more extreme schemes were ever attempted, and it describes the archive as a mix of real extortion records, abandoned plans, boasting and "violent fantasies."
The sources disagree on whether victims are named. Wire Observer says the chats do not name the companies. Recorded Future News says some of the organizations named in the archive have not publicly acknowledged a breach. This brief gives more weight to Recorded Future News, an established outlet that reviewed the material directly.
What Was Taken
The leak is the group's own data rather than a single victim's breach, so no single dataset was stolen here. What the chats document is SRG's business model: it steals data from professional services firms, mostly law firms, and threatens to leak it.
- Scale of payouts: About $207 million from 27 firms, according to SRG's own records. Wire Observer works out an average of about $7.7 million per victim. Chainalysis says one wallet named in the chats was funded entirely from a payment of more than $10 million that SRG collected from a victim in mid-2026, a payment Chainalysis was already tracking before the leak.
- Money movement: Crystal Intelligence reports that payouts followed strict wallet rules designed to frustrate tracing. The Register reports the chats also mention cash brokers. Chainalysis traced funds from leaked addresses to SRG expenses such as members' wages and IT infrastructure.
- Type of data: Material held by law firms, including attorney-client privileged files, M&A data, litigation strategy and regulated personal data. Recorded Future News describes one negotiation in which a New York firm said someone had walked into its office and copied files onto a flash drive. The firm said its executives had authorized $1 million, but it wanted proof that every digital and physical copy would be destroyed.
Several recent SRG victim claims fill in the picture, though none are confirmed:
- Hogan Lovells Cadwalader: DataBreaches.net reported on September 28 that SRG attacked the firm twice and came back after the firm refused to pay. According to an SRG spokesperson, the group got into Hogan Lovells' separately firewalled legacy infrastructure on August 12, 2026, stayed for about 24 hours, and exfiltrated data from several machines. The firm did not respond to requests for comment. DataBreaches.net treats the breach as unconfirmed but says nothing in the data it inspected suggested fabrication.
- Two large US law firms: Security Arsenal (OTHER) reports they were added to SRG's leak site on October 5. All of those listings come from a single crawler and have not been verified.
- Andersen Group Inc.: Brinztech (OTHER) reports the firm was listed on SRG's portal after it disclosed a social engineering attack on one employee that exposed files on "a limited number of clients." This brief has not independently confirmed the listing.
Why It Matters
Earlier ransomware models depended on encryption. SRG's leaked figures suggest that encryption isn't needed to make large sums from extortion. Taking the data and applying legal and reputational pressure appears to be enough, especially against law firms, whose business rests on confidentiality. Wire Observer calls this "double extortion," but the label doesn't really apply. Double extortion means encryption plus a leak threat, and SRG skips the encryption entirely. Defenses built around detecting encryption, such as canary files, mass file-rename alerts and backup restore drills, do nothing against this model.
According to DataBreaches.net, SRG has successfully attacked more than 100 law firms, and no victim has ever claimed SRG leaked fabricated data. That record gives its threats weight in negotiations. The Hogan Lovells Cadwalader case also shows that refusing to pay can bring a second intrusion.
The physical side is the most unusual part. The FBI warned in May 2026 that people posing as IT staff were entering law offices and copying files to USB drives. gblock.app reports that the leaked chats show these "agents" being recruited through Telegram job ads. A Russian extortion crew with paid people on the ground in the US is a hybrid insider/physical threat that most law firm security programs are not built to handle.
The Attack Technique
The sources agree on a layered approach to getting in:
- Callback phishing: The FBI's account, summarized by gblock.app, says intrusions start with an email, usually a fake subscription or invoice notice, that tells the target to call a phone number. That puts the victim on the phone with SRG operators.
- Fake IT support calls: Operators pretend to be the help desk and talk employees into installing legitimate remote-access tools or granting a remote session. After that, they exfiltrate data with standard file-transfer utilities.
- Physical intrusion as the fallback: If an employee refuses remote access, gblock.app reports, citing the FBI, that SRG sends an "agent" posing as IT personnel to the office to copy files onto a USB drive. Crystal Intelligence also notes that SRG has recently added in-person office visits.
- Hands-on access to separate infrastructure: In the Hogan Lovells Cadwalader case, SRG says it used "a new set of tools" to get into legacy systems that had their own firewall and authorization controls. It did not say what those tools were.
None of the sources describe malware deployment, encryption, or destructive activity. The intrusions are mainly social engineering followed by data theft using legitimate tools.
What Organizations Should Do
- Lock down IT support identity checks. Publish to all staff that IT will never cold-call asking for remote access, and require callbacks to a known internal number or ticket verification before any remote session. Train staff to treat invoice and subscription emails that include a phone number as suspicious.
- Allowlist remote monitoring and management (RMM) tools. Block unapproved remote-access software (AnyConnect-style lookalikes, Zoho Assist, AnyDesk, ScreenConnect and similar) at the endpoint. Alert on any new RMM install or first-time remote session to a user workstation.
- Verify physical visitors. Require advance tickets and escort for any "IT technician" coming on site. Confirm their identity with your actual IT team or managed service provider before they touch a device, and brief reception and office managers on the FBI's May 2026 warning.
- Control removable media. Block or log USB mass-storage writes on endpoints that handle client matters, and alert on large copies to removable drives.
- Watch for exfiltration, not encryption. Monitor for unusual outbound volume, use of cloud-storage and file-transfer utilities like rclone or WinSCP, and bulk access to document management systems. Assume legacy and merged-firm infrastructure is in scope.
- Plan for no-encryption extortion. Your incident response playbook should cover pure data-theft demands, including legal privilege handling, client notification, and the risk of a second attack if you decline to pay. Hunt against SRG tradecraft now rather than waiting for a leak-site listing.
Sources: Silent Ransom Group’s Chat Leaks Reveal $207 Million Data‑Extortion... | Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked... | Can you really make more than $200M in six months without encryptin... | Money trail backs leaked chats from extortion crew that walks ... | Leaked chats show Russian extortion gang sending 'agents ... | Silent Ransom Group Leak Shows Agents Sent Into US Law Firms | SILENTRANSOMGROUP Leak-Site Activity: 3 New Listings — Legal & Prof... | Andersen Group Inc. Listed on LeakedData (Silent Ransom ...