Leaked chats show Silent Ransom Group sending fake IT staff into US law firms
An archive of the extortion group's chats, reviewed by The Record, describes recruits posing as IT workers to physically enter offices and steal data from about 50 mostly legal-sector targets.
At a glance
- The archive spans thousands of messages from August 2025 to September 2026 and was posted to an .onion site in early October
- About 50 organizations appear, mostly law firms; the group claims roughly $200 million in settlements, an unverified figure
- Recruits were hired via Telegram ads to enter offices posing as IT personnel, with forged IDs and recording glasses
- Chainalysis linked crypto addresses in the leak to known Silent Ransom Group extortions
A leaked archive of internal chats from the Silent Ransom Group, a Russian-speaking extortion crew also tracked as Luna Moth and Chatty Spider, shows the gang recruiting "agents" to walk into US law firm offices posing as IT staff and copy sensitive data, according to an October 8 report by The Record from Recorded Future News. The leak offers a rare look at an operation that blends phone-based social engineering with physical intrusion.
What happened
According to The Record, an unidentified source posted the archive to a dedicated .onion site in early October without stating a motive. It contains thousands of messages from August 2025 to September 2026. The outlet said parts of the material were independently corroborated, but it could not verify the most extreme schemes described. Blockchain analysis firm Chainalysis linked cryptocurrency addresses in the leak to known Silent Ransom Group extortions, while saying it could not speak to the totality of the claims.
About 50 organizations appear in the chats, mostly law firms, The Record reported. Several have publicly disclosed cyber incidents this year. The group tracked negotiations through stages labelled "chat", "offer", "contract" and "gold", and its own figures claim dozens of firms reached the final stage with roughly $200 million in settlements. Those numbers are the group's and have not been verified. In one case, a New York firm was told someone had copied files onto a flash drive in its office; executives authorized a $1 million settlement but demanded proof that all copies would be destroyed.
Technical details
The chats describe recruiting people through paid Telegram ads disguised as ordinary jobs such as courier or security work, aimed at Russian speakers. Recruits were sent to enter offices posing as IT personnel, with plans that included a pizza-delivery ruse, disguises modeled on lawyers and smart glasses for recording. The group bought a UV printer and materials for fake ID cards and paid forgers, according to the report. The leader estimated that only about one in ten recruits was usable.
The Record also found discussions of following executives, blackmail and coercion, as well as talk of targeting a defense contractor employee and recruiting US sailors. The outlet stressed that none of these plans is shown to have been carried out and that it found no evidence of contact with the Russian state. By the end of the archive, members were discussing a relaunch under the name "Sleepless Threat".
Who is affected
Law firms and other professional services organizations that hold sensitive client data are the group's primary targets. The FBI had earlier issued a flash alert warning that Silent Ransom Group members pose as IT staff to gain access to computers.
What to do
Organizations should require out-of-band verification for any IT support call or on-site technician visit, escort and log all visitors, restrict the use of removable storage on workstations and train front-desk and legal staff to report unexpected IT requests. Monitoring for unusual remote management tool installations and large data copies to USB devices can help detect intrusions early.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



