Last updated 1 month ago
The Silent Ransom Group has launched an escalating extortion campaign targeting multiple law firms in the United States. The financially motivated group is combining vishing, IT impersonation, and in-person office intrusions to steal data and extort victims. The attacks have been ongoing, with the disclosure occurring in June 2026.
The attack chain involves initial access through vishing and impersonation of IT personnel, followed by in-person intrusions into law firm offices. The threat actor, Silent Ransom Group, uses these techniques to gain unauthorized physical access and steal sensitive data for extortion. The specific data types compromised have not been detailed, but the group's goal is financial extortion.
No post-incident details such as regulatory actions, litigation, ransom payments, or containment milestones have been reported in the article.
Combination of vishing, IT impersonation, and in-person office intrusions to steal data and extort victims
Law firms targeted by Silent Ransom Group should strengthen physical security controls and implement multi-factor authentication for all remote access, including IT support impersonation scenarios. The combination of vishing and in-person intrusions indicates a need for robust visitor management and employee training on social engineering tactics specific to IT impersonation.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor