discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

FBI: Get to know your IT guy – extortion crews are visiting law firms pretending to be tech support

The FBI says Silent Ransom Group is still targeting US law firms, now with in-person visits and USB-drive theft after phishing and remote access tricks fail.

By Connor Jones·May 27·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

The FBI says Silent Ransom Group is adapting its playbook against US law firms, mixing callback phishing, fake IT support, and physical walk-ins to steal data. When remote tricks fail, attackers reportedly use thumb drives to copy files and later extort victims.

Why it matters

Law firms hold sensitive client and case data, which makes them high-value targets for extortion crews. The story shows attackers are combining social engineering with physical access, so basic office controls now matter alongside email and MFA defenses.

A group of crooks is pretending to be office tech helpers. They call or email people, then try to get inside computers so they can copy private files.

If that does not work, they may even walk into the office in person and act like they are there to fix a problem. It is a bit like a thief wearing a store uniform to get through the front door.

The FBI says law firms are a big target because they keep very private information. It wants offices to lock down USB ports, check visitors carefully, and make sure workers do not trust unknown tech support calls.

Analysis

What the FBI says

The FBI says Silent Ransom Group, active since 2022 in its view, continues to target US law firms and their staff. The agency’s latest advisory says the crew is still posing as company IT support and has fresh attacks reported in spring 2026.

How the crew works

The group’s main play remains callback phishing. Victims receive an SMS or email that pushes them to call a number, where an attacker pretends to be help desk staff and tries to persuade them to approve remote access. Once inside, the attackers look for ways to raise privileges and steal data. The article says they may use tools such as WinSCP or a disguised version of Rclone, or move documents through internal services like Google Drive or Microsoft OneDrive.

When remote social engineering does not work, the FBI says members have been physically entering office buildings and continuing the fake IT routine in person. In those cases, they claim they need to image a device or make a backup to investigate a phishing problem. The real goal is to copy files onto a thumb drive for later extortion.

Why the legal sector is targeted

The FBI says law firms remain an attractive target because their data is highly sensitive. Silent Ransom Group is not described as a ransomware operator, but it does run a data leak site and threatens to publish stolen files unless victims pay. The article also notes Jones Day as a recent alleged victim.

What the FBI recommends

The bureau wants people to report evidence such as phone numbers, call transcripts, phishing emails, crypto wallet details, and identifying information about anyone entering office buildings. It also recommends blocking external USB drives, verifying visitors’ credentials, limiting access to sensitive data from less secure networks, using phishing-resistant MFA, blocking port 22, and training staff not to let strangers plug hardware into company machines.

Key points

  • The FBI says Silent Ransom Group is still targeting US law firms and pretending to be IT support.
  • When remote phishing fails, attackers may visit offices in person and use thumb drives to copy data.
  • The group uses stolen files as extortion leverage rather than classic ransomware encryption.
  • The FBI recommends blocking external drives, verifying visitors, and using phishing-resistant MFA.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritypolicysocietytech

Author

Connor Jones

Intelligence analysis by

GPT-5.4 Mini

Published

May 27, 2026

Source

theregister.com

Share

Topics

securitypolicysocietytech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…