Recent revelations have shed light on the activities of the Silent Ransom Group, a cybercriminal outfit accused of extorting over $206 million from 27 companies within a period of six months. Unlike typical ransomware attacks, this group reportedly did not encrypt data but instead threatened to disclose sensitive information unless demands were met.
Data Extortion: A New Cyber Threat
The extortion strategy employed by the Silent Ransom Group involves stealing crucial data and menacing victims with potential exposure. While the reported earnings have not been independently verified, the group has denied both the breach of their systems and the authenticity of leaked chat records. DataBreaches first reported these findings on October 7, highlighting significant conversations about ransom negotiations and internal operations.
The internal chat logs, covering a span from August 27, 2025, to September 29, 2026, provide insights into the group’s modus operandi. The records, which label successful extortion events as “GOLD,” suggest that the group amassed $206.95 million in payments during a short six-month span, though these figures are drawn from the perpetrators’ own accounts rather than validated financial audits.
Financial Transactions and Analysis
According to Crystal Intelligence, the median payment extracted by Silent Ransom Group was $6 million, with individual ransoms ranging from $100,000 to $30 million. Notably, White & Case was associated with the largest ransom amount. Several law firms were identified in the leaked chats, with nine confirming breaches during the relevant timeframe; however, these confirmations do not clarify the attackers’ identities or verify the corresponding ransom payments.
Further investigations revealed blockchain transactions consistent with the timeline of the chat entries. A significant wallet reportedly received 344 bitcoins, roughly valued at $27 million, over six weeks. Researchers, however, could not conclusively link individual payments to this wallet, indicating substantial monetary movement rather than providing definitive proof of the total extorted amount.
Targeting Law Firms and Exploiting IT Systems
Silent Ransom Group, also known as Luna Moth and UNC3753, arose post-Conti’s dissolution in 2022. Their focus has been on law firms, exploiting the sensitive client data they handle. The group achieves access by deceiving employees, masquerading as internal IT support to gain remote system entry. Utilizing legitimate software, they extract data without deploying typical ransomware that could trigger security alerts.
To enhance their operations, the attackers have created convincing fake helpdesk websites, making their intrusion tactics even more effective. Tools like WinSCP and Rclone facilitate the transfer of compromised files. While the threat of data exposure looms large, the group refrains from encrypting business systems, thereby avoiding immediate operational disruptions.
For cybersecurity professionals, this evolving threat model underscores the necessity of stringent identity verification procedures and robust employee training to recognize and thwart such deceptive tactics. Organizations must reinforce remote access protocols, implement phishing-resistant measures, and ensure staff are prepared to validate support requests through established channels.
