Security1 publisherNot yet confirmed elsewhere3 min readPublished
Silent Ransom Group sent recruited 'agents' into US law firm offices, leaked chats show
Leaked chats reviewed by Recorded Future News show the Silent Ransom Group directing US-based recruits it calls 'agents' into law firm offices. For firms holding client data, an intrusion can start at reception with someone posing as a courier or an IT worker.
The Watch · Security desk

What happened
- In one negotiation in the chats, a law firm told the extortionists it knew a person had entered its New York office and copied files onto a flash drive.
- That firm said its executives had authorized $1 million but wanted proof every digital and physical copy was destroyed, citing LockBit's failure to delete paying victims' data.
- The gang found its agents through paid Telegram ads disguised as courier, nightclub promotion and security jobs that appear aimed at Russian speakers.
- The group's apparent leader estimated in February that only one in 10 recruits proved usable, a figure he called the operation's conversion rate.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A visitor with a flash drive at a workstation reaches client files without crossing the network perimeter, so reception and IT-visit checks are now part of a law firm's data security.
- decision Once copies sit on physical media, settling buys no deletion a firm can verify. That weakens the case for paying at all.
- exposure Recruits hired through job ads may not know the purpose of the job, so the person at reception can present as an ordinary courier with no intent for staff to read.
The entry plan in the chats has two steps. One participant proposed buying delivery uniforms and insulated bags. "We buy these insulated bags and uniforms for agents," he wrote, describing an operative who would get past reception delivering pizza and then pose as an IT worker in the main office [10]. The FBI has already published the second step. A flash alert earlier this year warned that Silent Ransom Group members were posing as IT personnel to gain physical access to computers [7].
The gang budgeted for props. An earlier shopping list included a $3,200 printer with ultraviolet capability and holographic materials for producing ID cards, and the archive records money sent to forgers, one of them in New York [12]. Other members proposed custom masks modelled on real lawyers, and smart glasses for an agent posing as a client to record an office interior [11]. Nothing in the archive shows whether the pizza ruse or the masks were used [13].
The leak's origin is anonymous. The archive appeared on a bespoke .onion site in early October, posted by an unidentified source who did not state a motive [2]. It covers about 13 months of messages [19] and mixes apparent extortion records with brainstorming, abandoned plans, boasting and violent fantasies [4]. Chainalysis matched cryptocurrency addresses in it to known Silent Ransom Group extortions, but said it could not "speak to the totality of claims" in the archive [5][6]. The group is also tracked as Luna Moth and Chatty Spider [5].
The chats also describe plans to kidnap business executives and to recruit military personnel to spy on submarine-based nuclear forces [1]. Recorded Future News could not verify whether the most extreme schemes were ever attempted [4]. On current evidence those plans are talk. The office walk-in has a victim's own account in a negotiation and an FBI alert behind it [8][7].
Over those 13 months, members tracked dozens of victims and haggled over multimillion-dollar payments. Some organizations named in the chats have not publicly acknowledged a breach [3]. Recruitment was messy, according to the messages. A roster lists agents by numbered code and city, including a 17-year-old marked ready to work and noted as underage, and one channel name suggests an agent was caught in Chicago [15]. Some recruits vanished after being paid or backed out at office entrances. Others went on paid test assignments, and one member called the process a conveyor belt [16]. Recorded Future News compared the model to the disposable agents recruited by Russian and Iranian intelligence services [18].
Not every recruit was told the plan. One member suggested explaining the scheme fully only "to those who we trust fully" [17]. In my view the control that matters for a law firm sits at the desk and the workstation: confirming that someone the firm knows scheduled the IT visit before a stranger touches a machine. In both the FBI alert and the New York case, a stranger reached a computer inside the office [7][8].
What to watch
- Breach disclosures from organizations named in the chats that have not yet publicly acknowledged one.
- Any US arrest or charge tied to the agent the chats suggest was caught in Chicago.
- Independent checks of the archive beyond Chainalysis's address matches, especially on the kidnapping and military-recruitment plans.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption35
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Members of a Russia-based cyberextortion gang plotted to send operatives into US law firms, kidnap business executives and recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News.
- [2]
The archive was posted to a bespoke .onion site in early October by an unidentified source who did not state a motive, and contains thousands of messages from August 2025 to September 2026.
- [3]
In the messages, members track dozens of victims, haggle over multimillion-dollar payments and direct US-based operatives they call 'agents'. Some of the named organizations have not publicly acknowledged a breach.
- [4]
The archive mixes apparent records of real extortion with brainstorming sessions, abandoned plans, boasting and violent fantasies. Recorded Future News could not verify whether the most extreme schemes were ever attempted.
- [5]
Chainalysis examined cryptocurrency addresses contained in the leak and said it could tie them to known extortions by the Silent Ransom Group, which is also tracked as Luna Moth and Chatty Spider.
- [6]
Chainalysis cautioned that it could not "speak to the totality of claims" documented in the archive.
- [7]
An FBI flash alert earlier this year warned that members of the Silent Ransom Group were posing as IT personnel to gain physical access to computers; the FBI has documented the group recruiting 'agents' to physically infiltrate victims' offices.
- [8]
In one negotiation shared in the chats, a law firm's representative told the extortionists that the firm knew an individual had entered its New York office and copied files onto a flash drive.
- [9]
The firm said its executives had authorized $1 million to settle the demand but wanted proof that every digital and physical copy of its information would be destroyed, citing evidence that the LockBit ransomware gang had failed to delete data belonging to victims who paid.
- [10]
"We buy these insulated bags and uniforms for agents," one participant wrote, before outlining a pizza delivery ruse in which an operative would get through reception by delivering pizza and then pose as an IT worker in the main office.
- [11]
Another member proposed creating custom masks modelled on real lawyers, while a different member suggested purchasing smart glasses for an agent posing as a client to record the inside of an office.
- [12]
An earlier shopping list included a $3,200 printer with ultraviolet capabilities and holographic materials for producing identification cards. Expenses in the archive include funds sent to forgers, including one in New York.
- [13]
Nothing in the archive shows whether schemes like the pizza delivery ruse or lawyer masks were successfully used; the broader tactic of sending impostors into offices matches the FBI's account.
- [14]
The group recruited its 'agents' through paid Telegram advertisements disguised as ordinary job listings, including nightclub promotion, courier work and security; the ads appear to target Russian-speakers.
- [15]
The chats show the recruitment process was messy. A roster lists agents by numbered codes and city, with one entry describing a 17-year-old as ready to work while noting the recruit was underage. The name of another channel appears to indicate one of the group's agents had been caught in Chicago.
- [16]
The group's apparent leader estimated in February that only one in 10 recruits proved usable, calling it the operation's 'conversion' rate. Another member described the process as a conveyor belt. Some recruits disappeared after receiving money or backed out at office entrances; others were sent on paid test assignments.
- [17]
It is unclear whether every recruit understood the ultimate purpose; in one conversation a member suggested fully explaining the scheme only "to those who we trust fully."
- [18]
The group's physical access model depended on finding people willing to do the work, not unlike the disposable agents recruited by Russian and Iranian intelligence agencies.
- [19]
The leaked messages span about 13 months.
Sources
1 independent publisher whose own reporting we read for this story.
- therecord.mediaLeaked chats show Russian extortion gang sending ‘agents’ into US law firms
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Cyber ExtortionFollow
- Physical social engineeringFollow
- Law firm securityFollow