Silent Ransom Group Sends Fake IT Workers to Law Firms

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Silent Ransom Group targeted dozens of law firms from January through May, using fake IT workers who gained physical access to offices to steal data via USB drives or remote access tools
- Google Threat Intelligence and Mandiant published a report detailing the group’s use of in-person intrusions, including planting insiders or directly entering buildings to facilitate cyberattacks
- FBI issued an alert confirming multiple instances of individuals impersonating IT support staff to gain physical access to victim devices as part of the Silent Ransom Group’s data exfiltration scheme
- Silent Ransom Group employs a double-extortion tactic: threatening to leak stolen data on its own leak site and following through if ransom demands are not met, without encrypting files
- Hackers used social engineering, phishing emails, and phone calls to pose as IT support, tricking employees into joining screen-sharing sessions on Zoom or Microsoft Teams to bypass security controls
Why it matters: Law firms handling sensitive client data are now vulnerable not just to remote hacking but to physical infiltration, raising the cost and complexity of defense. The blend of digital and in-person tactics means traditional cybersecurity measures alone are no longer sufficient to prevent breaches.




