Securityaffairs.Co Silent Ransom Group Extorts $207 Million from Law Firms via Social Engineering
Article Content
- •Silent Ransom Group extorted $207 million from 27 law firms without encrypting files.
- •The group used social engineering tactics, primarily phone calls, to manipulate victims.
- •Internal chat leaks revealed operational strategies and financial dealings of the group.
The Silent Ransom Group reportedly extorted $207 million from 27 law firms over six months using social engineering tactics instead of traditional ransomware methods. The group relied on phone calls to manipulate victims into paying ransoms, with a median payment of $6 million and the largest single payment being $30 million from White & Case. Internal chat leaks revealed their operational strategies and financial dealings, including cryptocurrency transactions. The group's activities spanned from April to September 2026, with blockchain analysis supporting the scale of the operation. The leak, shared by researcher Tammy Harper, included discussions about future targets and personal matters among members. The report indicates that the group employed sophisticated money laundering techniques to obscure their financial activities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Silent Ransom Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How did the Silent Ransom Group operate?
What was the total amount extorted?
What evidence supports these claims?
Continue Reading
Metaencryptor Ransomware Attack Targets AECOM AECOM, a Texas-based infrastructure consulting firm, reportedly suffered a ransomware attack attributed to the hacker group Metaencryptor. The breach, which was discovered on September 17, 2026, is believed to have compromised approximately 1.22 terabytes of data. The attack was confirmed by dark web monitoring site…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…