25 US law firms are on one extortion crew's leak site

Ten new entries went up on a data extortion site this week with the victims' names blanked out, reduced to a few initials and a row of dots. If the pattern of the past five months holds, all ten are American law firms.

Each organization that Silent Ransom Group has named on its leak site during 2026 has been a law firm in the United States. IntelFusions tracking counts 25 distinct firms since 16 March, among them Jones Day, Mayer Brown, Jackson Lewis, Fox Rothschild and Troutman Pepper Locke. No manufacturer, hospital or retailer appears anywhere on the list. The appeal is obvious: a law firm is a concentrated store of other people's secrets. It also explains the missing encryptor, since there is little point switching the lights off when the leverage is the filing cabinet.

The blanks get filled in later

The masked entries are not a glitch, they are the pressure. The crew posts a redacted name first, marks it as pending disclosure, and fills in the missing letters if the firm does not pay. Our own records caught that working: on 12 August the site carried listings for R...er and R... D... alongside the full name Riker Danzig, and on 18 August an entry reading T... P... L... resolved into Troutman Pepper Locke. Ten firms sit in that window now, eight added on 26 August and two more on 27 August, the largest batch this campaign has produced.

These are unverified claims published by criminals on their own site, assertions rather than confirmed breaches.

The caller claims to be from IT

The FBI's Internet Crime Complaint Center set out how the group works in a FLASH advisory published on 26 May 2026. Silent Ransom Group, also tracked as Luna Moth, Chatty Spider and UNC3753, encrypts nothing. Its operators telephone staff, or send emails designed to make staff telephone them, then pose as the company's own IT department and talk an employee into opening a remote session. Where that fails, the FBI says, the group has sent someone to the building in person, to plug a storage device into the machine.

From there they escalate privileges only as far as needed and copy data straight out, using WinSCP or a renamed copy of Rclone, or pushing files into the firm's own Google Drive or OneDrive so the traffic looks unremarkable. The bureau records victims in insurance, finance and healthcare too, but says the group has "consistently targeted US-based law firms since Spring 2023". The tactic is not unique to this crew: fake IT support calls have been arriving over Microsoft Teams and ending in ransomware.

Verify the person, then the password

The FBI's advice here is unusually physical, because the group is. Check the identity of anyone turning up to ask for access to a machine, including a copy of their ID. Write down how IT will contact staff and prove who it is, then tell everyone about it. Disable remote access and external drive permissions on machines holding confidential material, and require phishing-resistant multi-factor authentication where you can.

Every tool involved is legitimate

Detection is awkward because there is no malware to find. The FBI's indicators are ordinary software turning up where it does not belong: new installs of Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop or Atera; WinSCP or Rclone connecting outbound; USB drives on machines holding client files; and staff reporting unsolicited calls from people claiming to be internal IT. Stolen files are published at business-data-leaks[.]com. Administrators use all of them daily, so treat each as a question, not a verdict.

The ten blanked-out entries are a countdown, and the firms behind them already know which line is theirs. For everyone else, the detail that matters is where this starts: somebody believing a voice on the telephone.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions