Skip to content

Security1 publisherNot yet confirmed elsewhere3 min readPublished

Silent Ransom Group sent recruited 'agents' into US law firm offices, leaked chats show

Leaked chats reviewed by Recorded Future News show the Silent Ransom Group directing US-based recruits it calls 'agents' into law firm offices. For firms holding client data, an intrusion can start at reception with someone posing as a courier or an IT worker.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Silent Ransom Group sent recruited 'agents' into US law firm offices, leaked chats show
Generated illustration

What happened

  • In one negotiation in the chats, a law firm told the extortionists it knew a person had entered its New York office and copied files onto a flash drive.
  • That firm said its executives had authorized $1 million but wanted proof every digital and physical copy was destroyed, citing LockBit's failure to delete paying victims' data.
  • The gang found its agents through paid Telegram ads disguised as courier, nightclub promotion and security jobs that appear aimed at Russian speakers.
  • The group's apparent leader estimated in February that only one in 10 recruits proved usable, a figure he called the operation's conversion rate.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A visitor with a flash drive at a workstation reaches client files without crossing the network perimeter, so reception and IT-visit checks are now part of a law firm's data security.
  • decision Once copies sit on physical media, settling buys no deletion a firm can verify. That weakens the case for paying at all.
  • exposure Recruits hired through job ads may not know the purpose of the job, so the person at reception can present as an ordinary courier with no intent for staff to read.

The entry plan in the chats has two steps. One participant proposed buying delivery uniforms and insulated bags. "We buy these insulated bags and uniforms for agents," he wrote, describing an operative who would get past reception delivering pizza and then pose as an IT worker in the main office [10]. The FBI has already published the second step. A flash alert earlier this year warned that Silent Ransom Group members were posing as IT personnel to gain physical access to computers [7].

The gang budgeted for props. An earlier shopping list included a $3,200 printer with ultraviolet capability and holographic materials for producing ID cards, and the archive records money sent to forgers, one of them in New York [12]. Other members proposed custom masks modelled on real lawyers, and smart glasses for an agent posing as a client to record an office interior [11]. Nothing in the archive shows whether the pizza ruse or the masks were used [13].

The leak's origin is anonymous. The archive appeared on a bespoke .onion site in early October, posted by an unidentified source who did not state a motive [2]. It covers about 13 months of messages [19] and mixes apparent extortion records with brainstorming, abandoned plans, boasting and violent fantasies [4]. Chainalysis matched cryptocurrency addresses in it to known Silent Ransom Group extortions, but said it could not "speak to the totality of claims" in the archive [5][6]. The group is also tracked as Luna Moth and Chatty Spider [5].

The chats also describe plans to kidnap business executives and to recruit military personnel to spy on submarine-based nuclear forces [1]. Recorded Future News could not verify whether the most extreme schemes were ever attempted [4]. On current evidence those plans are talk. The office walk-in has a victim's own account in a negotiation and an FBI alert behind it [8][7].

Over those 13 months, members tracked dozens of victims and haggled over multimillion-dollar payments. Some organizations named in the chats have not publicly acknowledged a breach [3]. Recruitment was messy, according to the messages. A roster lists agents by numbered code and city, including a 17-year-old marked ready to work and noted as underage, and one channel name suggests an agent was caught in Chicago [15]. Some recruits vanished after being paid or backed out at office entrances. Others went on paid test assignments, and one member called the process a conveyor belt [16]. Recorded Future News compared the model to the disposable agents recruited by Russian and Iranian intelligence services [18].

Not every recruit was told the plan. One member suggested explaining the scheme fully only "to those who we trust fully" [17]. In my view the control that matters for a law firm sits at the desk and the workstation: confirming that someone the firm knows scheduled the IT visit before a stranger touches a machine. In both the FBI alert and the New York case, a stranger reached a computer inside the office [7][8].

What to watch

  • Breach disclosures from organizations named in the chats that have not yet publicly acknowledged one.
  • Any US arrest or charge tied to the agent the chats suggest was caught in Chicago.
  • Independent checks of the archive beyond Chainalysis's address matches, especially on the kidnapping and military-recruitment plans.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption35
Hype gap+15
Incentives
Insufficient
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Members of a Russia-based cyberextortion gang plotted to send operatives into US law firms, kidnap business executives and recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News.

    ReportedSupportedSource: Recorded Future NewsView cited source
  2. [2]

    The archive was posted to a bespoke .onion site in early October by an unidentified source who did not state a motive, and contains thousands of messages from August 2025 to September 2026.

    ReportedSupportedSource: Recorded Future NewsView cited source
  3. [3]

    In the messages, members track dozens of victims, haggle over multimillion-dollar payments and direct US-based operatives they call 'agents'. Some of the named organizations have not publicly acknowledged a breach.

    ReportedSupportedSource: Recorded Future NewsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. therecord.media

    1 article · October 8, 2026

    Leaked chats show Russian extortion gang sending ‘agents’ into US law firms

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories