Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AT&T Fined $177M for Two Customer Data Breaches
October 10, 2026
Critical AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root
October 9, 2026
GhostAction Attack Steals Secrets from GitHub Repositories
October 9, 2026
Home/CyberSecurity News/Silent Ransomware Group Extorted $200M Without Encryption, Leaked Chats Reveal
CyberSecurity News

Silent Ransomware Group Extorted $200M Without Encryption, Leaked Chats Reveal

Key Takeaways Leaked internal communications from the Silent Ransom Group (also known as Luna Moth or UNC3753) indicate the group extorted over $200 million from 27 organizations. The group achieved...

David kimber
David kimber
October 9, 2026 4 Min Read
23 0

Key Takeaways

  • Leaked internal communications from the Silent Ransom Group (also known as Luna Moth or UNC3753) indicate the group extorted over $200 million from 27 organizations.
  • The group achieved this significant sum through data extortion, threatening to publish stolen sensitive information rather than encrypting systems.
  • Law firms were a primary target due to their access to confidential client data, with several prominent firms allegedly paying millions.
  • The group employed social engineering tactics, impersonating IT support to gain remote access and exfiltrate data.

Cyber Extortionists Allegedly Rake In $200M Without Encrypting Victims

Alleged internal chat logs from the Silent Ransom Group suggest the cybercriminal entity amassed approximately $206.95 million from 27 companies over roughly six months, primarily through data extortion rather than traditional ransomware encryption. This substantial figure underscores the growing efficacy of tactics focused solely on stealing and threatening to leak sensitive data.

Table Of Content

  • Key Takeaways
  • Cyber Extortionists Allegedly Rake In $200M Without Encrypting Victims
  • The Mechanics of a Multi-Million Dollar Extortion Operation
  • Alleged Payments by Named Victims
  • Tactics and Tradecraft of Silent Ransom Group
  • What You Should Do

While the reported earnings highlight a lucrative shift in cybercrime methodology, the stated payment figures remain unverified. The Silent Ransom Group itself has denied any system breach or the authenticity of the leaked communications.

The alleged leak, first reported by DataBreaches on October 7, includes 5,692 messages spanning from August 27, 2025, to September 29, 2026. These discussions reportedly detail victim negotiations, payment confirmations, methods of initial access, and the spending habits of group members. A subsequent update on October 8 noted that the Silent Ransom Group had agreed to an interview but disputed the origin of the leaked materials.

The Mechanics of a Multi-Million Dollar Extortion Operation

Within the leaked chats, completed deals are marked as “GOLD,” and aggregating these entries yields the reported $206.95 million total. According to Crystal Intelligence, the 27 purported payments occurred between April 3 and September 24, 2026, placing the alleged earnings within a period of under six months. It is crucial to note that these figures represent the criminals’ own internal records, not independently audited financial statements.

According to DataBreaches, the median alleged payment was $6 million, with individual ransoms ranging from $100,000 to a staggering $30 million. White & Case was associated with the largest reported payment. While nine named firms publicly disclosed breaches relevant to this period, these disclosures do not definitively confirm the Silent Ransom Group as the attacker or verify the payment amounts shown in the leaked chats.

Crystal Intelligence’s blockchain analysis identified cryptocurrency transactions that align with the timing of several chat entries. One upstream collection wallet reportedly received approximately 344 Bitcoin, valued at around $27 million, over a six-week span. However, researchers were unable to directly link individual victim payments to this specific wallet, meaning the blockchain evidence supports significant financial activity by the group but does not independently confirm the total headline figure.

Alleged Payments by Named Victims

Law Firm Reported Payment Breach Confirmation
Beveridge & Diamond $1,000,000 Not provided
Blank Rome $17,500,000 Confirmed May 2026 breach; attorney tricked into uploading files to Google Drive.
Bowman and Brooke $100,000 Not provided
Buchalter $10,000,000 Confirmed August 2026 data breach involving client and patient information.
Chartwell $1,000,000 Confirmed April 2026 social-engineering incident.
Cox Castle $600,000 Not provided
Dentons $21,000,000 Not provided
Dickie, McCamey & Chilcote $450,000 Not provided
F3 Law $400,000 Not provided
Fragomen $10,500,000 Confirmed May 2026 account compromise.
Goodwin Procter $10,000,000 Confirmed employee credential theft in spring 2026.
Goulston & Storrs $450,000 2026 data breach involving driver’s licenses.
Gray Reed $500,000 Not provided
Hinshaw & Culbertson $8,000,000 Not provided
Irell & Manella $275,000 Not provided
Jackson Lewis $3,900,000 Not provided
K&L Gates $3,000,000 Not provided
Manatt $6,000,000 Not provided
McDermott Will & Schulte $11,000,000 Confirmed May 2026 incident affecting personal data.
Phelps $575,000 Not provided
Proskauer Rose $8,000,000 Not provided
Rivkin Radler $700,000 Not provided
Squire Patton Boggs $20,000,000 Not provided
Taft $6,000,000 Confirmed March 2026 breach involving Social Security numbers.
Weil $19,000,000 Confirmed attack; ransom payment unverified.
White & Case $30,000,000 Not provided
WilmerHale $17,000,000 Confirmed May 2026 data breach.
Total Reported $206,950,000

Tactics and Tradecraft of Silent Ransom Group

The Silent Ransom Group, also known as Luna Moth or UNC3753, emerged following the dissolution of the Conti ransomware operation in 2022. Despite its “ransomware” moniker, the group primarily focuses on data exfiltration and extortion, bypassing the need for file encryption. Their modus operandi involves deceiving employees into granting remote access, subsequently stealing sensitive documents, and then demanding payment to prevent public disclosure.

Law firms have been a significant target for this group, largely due to the highly confidential client information they possess. The group has previously been observed employing IT support impersonation attacks against these firms. Attackers initiate contact with employees, posing as internal technical support staff, and then manipulate them into providing remote access to their systems. The use of legitimate remote access software helps these activities blend into normal operational workflows, reducing the likelihood of detection by conventional security tools that might flag malware.

Prior reporting on Luna Moth has highlighted their use of fake helpdesk domains, meticulously designed to mimic legitimate corporate support services. Once access is gained, tools like WinSCP and Rclone are commonly used to facilitate the transfer of stolen files. The leverage in these attacks stems from the potential reputational and legal damage caused by the disclosure of confidential records, rather than the immediate operational disruption of encrypted systems.

Crystal Intelligence’s analysis of the leaked chats also revealed instructions to use distinct cryptocurrency wallets for each victim, keep funds separate, and avoid commingling payouts. However, operators occasionally disregarded these rules, inadvertently creating traceable transaction links for investigators. Smaller payments were sometimes funneled through regulated exchanges, potentially generating leads through customer identity records. The analysis further detailed methods of cash conversion, including instant exchangers, couriers, and a Bitcoin-to-Zelle service.

What You Should Do

  • Verify Support Requests: Employees must verify any unsolicited IT support requests through established, known internal channels (e.g., a dedicated helpdesk number or portal) before granting remote access or providing credentials.
  • Implement Phishing-Resistant MFA: Deploy and enforce phishing-resistant multi-factor authentication (MFA) across all systems, especially for remote access and critical applications.
  • Strengthen Remote Access Controls: Implement strict controls over remote access, ensuring that only authorized personnel can connect from approved devices and locations.
  • Conduct Regular Security Awareness Training: Provide ongoing training to staff, specifically focusing on social engineering tactics, impersonation attempts, and the risks associated with granting unauthorized remote access.
  • Monitor for Data Exfiltration: Implement robust data loss prevention (DLP) solutions and monitor network traffic for unusual or large-scale data transfers to external destinations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityMalwarephishingransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Malicious PDF Reader on Google Play Delivers Anatsa Banking Trojan

Next Post

VirusTotal Scans Public IPv4 Space for C2 Servers and Malware Infrastructure

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CastleStealer Malware Bypasses Browser Security, Gains Remote Access
October 9, 2026
New Agentic AI Red Team Checklist Adds 222 Tests for 20 Attack Categories
October 9, 2026
Warden Stealer Spreads Via Malvertising and Cracked Software
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us