FBI warns of in-person data theft attacks from extortion gang
The FBI says Silent Ransom Group now sends people in person to steal data after IT impersonation and phishing fail.
Intelligence analysis by GPT-5.4 Mini

The FBI says the Silent Ransom Group is escalating from phone and email trickery to sending someone physically to victims’ offices to plug in storage devices and steal data.
A crime group is trying a new trick. First, it calls or emails people and pretends to be the company’s computer helper.
If that does not work, it may send a real person to the office. That person tries to plug in a device and copy files, like sneaking a copy of a key instead of picking a lock.
The FBI is warning companies so they can spot fake helpers, unknown visitors, and strange USB drives before important files are stolen.
Analysis
What the FBI says
The FBI warned that Silent Ransom Group, also tracked as Luna Moth, Chatty Spider, and UNC3753, is using a new tactic against U.S.-based law firms: in-person data theft. According to the alert, actors first pose as someone from the victim’s IT team and try to steer employees into calling them back or opening a remote desktop session.
If the remote approach does not work, the group may send a person to the victim’s location to get physical access to a computer. The FBI says that person may plug in a USB drive or external hard drive to copy data directly from the machine.
The agency listed warning signs that include unauthorized external storage devices being installed on company computers and unknown people claiming to be IT support while trying to access systems. The group then uses the stolen files for extortion, threatening to sell or publish the data on a leak site and, in some cases, calling employees or clients to increase pressure.
Longer-running campaign
The FBI said the group has been active since at least 2022 and has targeted legal and financial organizations in the U.S. since early 2023. BleepingComputer also noted the group’s ties to earlier BazarCall campaigns and said the actors split from the Conti ecosystem after its shutdown in March 2022.
The warning follows a May 2025 FBI notice about callback phishing and social engineering against law firms, and a May 2025 EclecticIQ report that described typosquatted domains used to impersonate support portals.
Key points
- The FBI says Silent Ransom Group is using in-person theft after phishing and phone-based tricks.
- Attackers pose as IT support to get employees to open remote access or call them back.
- If that fails, the group may send someone physically to the victim’s site to steal data from a computer.
- The FBI says law firms are a main target, along with financial organizations.
- The group uses stolen files to extort victims and threaten leaks.



