Therecord.Media Russian Gang Targets US Law Firms with Extortion Tactics
Article Content
- •Silent Ransom Group plans to infiltrate U.S. law firms for extortion.
- •Two law firms named with ransom demands of $4.9M and $8M.
- •FBI warns of physical infiltration tactics used by the gang.
Leaked chats from the Silent Ransom Group, a Russia-based cyberextortion gang, reveal plans to infiltrate U.S. law firms, kidnap executives, and recruit military personnel for espionage. The chats, spanning from August 2025 to September 2026, detail negotiations with law firms, including demands for multimillion-dollar ransoms. Two firms, Sheppard Mullin and Nelson Mullins, were specifically named, with ransom offers of $4.9 million and $8 million, respectively. The FBI has documented the group's unusual tactic of sending 'agents' to physically access victims' offices. The authenticity of the ransom claims has not been verified, and neither law firm has confirmed a breach. The group has previously used phishing and fake IT support calls to exfiltrate data without traditional ransomware encryption. The situation remains fluid as investigations continue.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Lockbit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What law firms are affected?
Are the ransom demands verified?
What tactics is the gang using?
Continue Reading
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…
Threat Actors Exploit Windows Shadow Copies for Ransomware and Credential Theft Cybercriminals are increasingly abusing Microsoft’s Volume Shadow Copy Service (VSS) to facilitate ransomware attacks and steal credentials. They achieve this by deleting recovery options before deploying ransomware and extracting sensitive data from protected files, including the Active Directory database. Tools such…