FBI: Get to know your IT guy – extortion crews are visiting law firms pretending to be tech support
The FBI says Silent Ransom Group is still targeting US law firms, now with in-person visits and USB-drive theft after phishing and remote access tricks fail.
Intelligence analysis by GPT-5.4 Mini
The FBI says Silent Ransom Group is adapting its playbook against US law firms, mixing callback phishing, fake IT support, and physical walk-ins to steal data. When remote tricks fail, attackers reportedly use thumb drives to copy files and later extort victims.
A group of crooks is pretending to be office tech helpers. They call or email people, then try to get inside computers so they can copy private files.
If that does not work, they may even walk into the office in person and act like they are there to fix a problem. It is a bit like a thief wearing a store uniform to get through the front door.
The FBI says law firms are a big target because they keep very private information. It wants offices to lock down USB ports, check visitors carefully, and make sure workers do not trust unknown tech support calls.
Analysis
What the FBI says
The FBI says Silent Ransom Group, active since 2022 in its view, continues to target US law firms and their staff. The agency’s latest advisory says the crew is still posing as company IT support and has fresh attacks reported in spring 2026.
How the crew works
The group’s main play remains callback phishing. Victims receive an SMS or email that pushes them to call a number, where an attacker pretends to be help desk staff and tries to persuade them to approve remote access. Once inside, the attackers look for ways to raise privileges and steal data. The article says they may use tools such as WinSCP or a disguised version of Rclone, or move documents through internal services like Google Drive or Microsoft OneDrive.
When remote social engineering does not work, the FBI says members have been physically entering office buildings and continuing the fake IT routine in person. In those cases, they claim they need to image a device or make a backup to investigate a phishing problem. The real goal is to copy files onto a thumb drive for later extortion.
Why the legal sector is targeted
The FBI says law firms remain an attractive target because their data is highly sensitive. Silent Ransom Group is not described as a ransomware operator, but it does run a data leak site and threatens to publish stolen files unless victims pay. The article also notes Jones Day as a recent alleged victim.
What the FBI recommends
The bureau wants people to report evidence such as phone numbers, call transcripts, phishing emails, crypto wallet details, and identifying information about anyone entering office buildings. It also recommends blocking external USB drives, verifying visitors’ credentials, limiting access to sensitive data from less secure networks, using phishing-resistant MFA, blocking port 22, and training staff not to let strangers plug hardware into company machines.
Key points
- The FBI says Silent Ransom Group is still targeting US law firms and pretending to be IT support.
- When remote phishing fails, attackers may visit offices in person and use thumb drives to copy data.
- The group uses stolen files as extortion leverage rather than classic ransomware encryption.
- The FBI recommends blocking external drives, verifying visitors, and using phishing-resistant MFA.



