Opens in a new tab

Silent Ransom Group Leak Gains Credibility

Leaked chats hint at SRG’s law firm extortion tactics, partially backed by blockchain trails

The Silent Ransom Group leak has gained limited credibility after blockchain researchers connected some disclosed cryptocurrency addresses to known extortion payments. However, researchers have not authenticated the complete collection or its headline financial claims.

What the Silent Ransom Group leak contains

The collection appeared anonymously under the title “The Luna Moth Files” and was first publicly analysed by Crystal Intelligence on 6 October 2026. It allegedly contains 5,692 internal messages dating from August 2025 to September 2026, together with cryptocurrency wallet addresses, operational discussions and a “deal board” recording victims and payments.

The messages are attributed to Silent Ransom Group, also tracked as Luna Moth, Chatty Spider and UNC3753. Despite its name, the group generally does not deploy file-encrypting ransomware. It steals sensitive information and threatens to publish it unless the victim pays.

The leaked chats claim that the group received approximately $207 million from 27 firms between April and September 2026. Neither Crystal Intelligence nor Chainalysis has verified that total, and both have stressed that their blockchain findings authenticate only parts of the material.

Crystal traces transactions described in the chats

Crystal Intelligence examined wallet addresses in the Silent Ransom Group leak and found that some transactions occurred at times consistent with the conversations. Its researchers traced funds to an upstream collection wallet that had received approximately 2,675 Bitcoin over its lifetime, but this does not prove that all of those funds belonged to SRG or came from the listed victims.

The analysis also described how the alleged operators moved and converted their proceeds. Funds reportedly passed through single-use addresses before reaching affiliates, instant cryptocurrency exchangers and services that paid money into Russian bank cards.

For larger conversions, the chats referred to a Moscow-based broker named “Zhenya”, who allegedly provided physical cash in return for cryptocurrency. Members reportedly suspected that the broker was taking an excessive margin through the exchange rate. These details come from Crystal’s analysis and have not been independently authenticated.

Another service, advertised on Telegram as SAFU Exchange, allegedly offered Bitcoin-to-Zelle transactions. Crystal associated the same online handle with a Georgia-based exchange that it describes as unlicensed and flagged for sanctions risk.

Some smaller payments allegedly went directly to exchange accounts belonging to field operatives and document forgers. Because regulated exchanges normally collect identity information, Crystal described these transfers as a potential weak point that could help law enforcement connect online identities with real people.

Blockchain evidence partially supports the leak

On 7 October 2026, Chainalysis publicly confirmed that certain addresses from the Silent Ransom Group leak matched information already held in its intelligence systems. The company said those addresses sat downstream of millions of dollars in extortion payments obtained from victims.

One wallet identified as belonging to an SRG member was reportedly funded entirely from a victim payment of approximately $10 million made in mid-2026. Chainalysis had been tracking that payment before the files appeared, making this evidence more significant than a connection established solely from the leaked material.

Transaction histories for two disclosed addresses also showed hundreds of thousands of dollars arriving from a wallet associated with a known group member. Chainalysis assessed that the money came from a large extortion payment and was subsequently used for expenses such as infrastructure and members’ wages.

On 8 October 2026, reporting brought together Chainalysis’ partial confirmation and Crystal’s analysis of the alleged laundering network. The findings strengthen the possibility that at least some messages, wallets and payment discussions are genuine. They do not establish that every chat is authentic, every named victim paid, or the claimed $207 million total is accurate.

Timeline of the current disclosures

  • 26 May 2026: The FBI issues FLASH-20260526-01, warning that SRG is targeting US law firms through IT-themed social engineering and physical intrusions.
  • 6 October 2026: Crystal Intelligence publishes the first identified public analysis of The Luna Moth Files and reports partial transactional corroboration.
  • 7 October 2026: Chainalysis confirms publicly that some leaked addresses are connected to known SRG extortion proceeds.
  • 8 October 2026: Further reporting details the cryptocurrency tracing, cash-out methods and important limits on authenticating the material.

How Silent Ransom Group attacks law firms

The Silent Ransom Group leak is notable because the operational claims align with an FBI warning issued before the files became public. The FBI confirmed that the group was actively targeting US law firms through callback phishing, remote access and, when remote social engineering failed, in-person impostors.

An attack can begin with an IT-themed email or telephone call. A target is encouraged to call a supplied number, follow technical instructions, install remote access software or accept a screen-sharing session. The attacker then operates through the employee’s legitimate session and attempts to reach valuable documents.

In its more unusual physical technique, SRG sends someone to the victim’s office posing as IT support. The impostor attempts to connect removable media, such as a USB device or external hard drive, to a workstation and copy information directly.

Once access is available, the objective is rapid data theft rather than encryption. The FBI has observed the use of WinSCP and hidden or renamed copies of Rclone, with stolen data transferred to destinations including Google Drive and Microsoft OneDrive.

This is not a software vulnerability, so there are no affected product versions or security patches. Legitimate administration, transfer and cloud services are being misused after attackers deceive staff or gain physical access. Exploitation is confirmed in the wild against US law firms during 2026.

Who is affected and why the case matters

The confirmed campaign is focused on US law firms, although SRG has also targeted other types of organisation. Legal practices are attractive because they hold commercially sensitive documents, privileged communications and information relating to transactions, litigation and clients.

The methods are also relevant to UK professional services businesses. Callback phishing works across borders, while offices with outsourced IT, lightly staffed reception areas or inconsistent visitor checks may be vulnerable to an individual claiming to be an authorised engineer.

The financial analysis matters because it connects parts of the alleged internal discussion with independently observed payments. It may also provide investigative routes through regulated exchange accounts, even though the wider Silent Ransom Group leak remains unverified.

Actions organisations should take now

Controls should address the specific combination of remote impersonation, physical access and legitimate data-transfer tools used in this campaign:

  • Verify unexpected IT support calls through a separately obtained, approved contact method before granting access or following instructions.
  • Require reception staff to confirm all engineers and other technical visitors with an authorised internal contact.
  • Block or tightly control removable media, particularly on systems containing sensitive legal or commercial data.
  • Monitor for unexpected WinSCP activity, Rclone execution or renamed binaries, and unusual transfers to Google Drive or OneDrive.
  • Investigate connections with business-data-leaks[.]com, which the FBI identified as an SRG site used to publish victim information.

Organisations should treat the leaked financial totals cautiously while taking the documented intrusion methods seriously. The blockchain evidence supports portions of the files, and the FBI has independently confirmed that the underlying social engineering and physical intrusion activity is already occurring.

Originally reported by theregister.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins
Category
Phishing & Social Engineering
Published
Oct 8 - 2026
Post Tags
Cypro firewall showing robust network security
Secure your business.
Elevate your security, accelerate your growth. We take care of cyber security for high-growth companies, at every stage of their journey.
Get in touch

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call