Leaked Chat Logs Show Silent Ransomware Extorted Over $200,000,000 in 6 Months Without Encrypting Data
Leaked Silent Ransom Group chats indicate $206.95 million extorted from 27 firms, mostly law firms, via data theft and publication threats without encryption.
DataBreaches reported 5,692 leaked internal messages spanning August 2025 to September 2026, where 'GOLD'-marked completed deals total $206.95 million from 27 victims, including $30 million attributed to White & Case. Crystal Intelligence dated the payments between April 3 and September 24, 2026 (median $6 million) and traced one upstream wallet receiving about 344 BTC (~$27 million), though the headline total remains unverified and the group denies the leak. Silent Ransom Group, also tracked as Luna Moth and UNC3753, emerged after Conti's 2022 shutdown and uses fake IT-support phone calls to gain remote access, exfiltrates files with tools like WinSCP and Rclone, and extorts victims by threatening to publish confidential records.
- 27 firms reportedly paid $206.95M; median $6M, range $100K-$30M; figures unverified
- Victims dominated by law firms including White & Case, Dentons, Squire Patton Boggs, WilmerHale
- Operators pose as IT support, gain remote access, exfiltrate with WinSCP/Rclone, threaten publication
- Blockchain analysis traced ~344 BTC (~$27M) to one collection wallet over six weeks
- Laundering used fresh wallets, instant exchangers, couriers, and a Bitcoin-to-Zelle service
Full article769 words · extracted from cybersecuritynews.com · click to collapse
Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files.
The reported earnings point to the power of data extortion, where attackers steal sensitive records and demand payment to keep them private. However, the payment figures remain unverified, and the group denies breaching its systems or leaking its chats.
DataBreaches reported the alleged leak on October 7. The material contains 5,692 messages covering August 27, 2025, through September 29, 2026.
Discussions reportedly include victim negotiations, payments, access methods, and members’ spending. An October 8 update said Silent Ransom Group had agreed to an interview but disputed the leak’s origin.
Silent Ransomware Extorted Over $200,000,000
The chats mark completed deals as “GOLD.” Adding those entries produces the $206.95 million total. Crystal Intelligence dates the 27 claimed payments between April 3 and September 24, 2026, placing the reported earnings within a period of less than six months. These entries reflect the criminals’ own records, not audited financial results.
According to DataBreaches, the median alleged payment was $6 million, while individual amounts ranged from $100,000 to $30 million. White & Case was listed against the largest amount. Nine named firms disclosed breaches relevant to the period. However, those disclosures do not confirm who attacked them or whether they paid the sums shown.
Crystal Intelligence’s blockchain analysis found transactions matching the timing of several chat entries. One upstream collection wallet received about 344 bitcoin, valued at roughly $27 million, over six weeks.
Researchers could not connect individual victim payments to that wallet. Hence, the evidence supports substantial money movement rather than proving the headline total.
Payments by 27 Victims Named in Leaked Chats :
| Law Firm | Reported Payment | Breach Confirmation |
|---|---|---|
| Beveridge & Diamond | $1,000,000 | Not provided |
| Blank Rome | $17,500,000 | Confirmed May 2026 breach; attorney tricked into uploading files to Google Drive. |
| Bowman and Brooke | $100,000 | Not provided |
| Buchalter | $10,000,000 | Confirmed August 2026 data breach involving client and patient information. |
| Chartwell | $1,000,000 | Confirmed April 2026 social-engineering incident. |
| Cox Castle | $600,000 | Not provided |
| Dentons | $21,000,000 | Not provided |
| Dickie, McCamey & Chilcote | $450,000 | Not provided |
| F3 Law | $400,000 | Not provided |
| Fragomen | $10,500,000 | Confirmed May 2026 account compromise. |
| Goodwin Procter | $10,000,000 | Confirmed employee credential theft in spring 2026. |
| Goulston & Storrs | $450,000 | 2026 data breach involving driver’s licenses. |
| Gray Reed | $500,000 | Not provided |
| Hinshaw & Culbertson | $8,000,000 | Not provided |
| Irell & Manella | $275,000 | Not provided |
| Jackson Lewis | $3,900,000 | Not provided |
| K&L Gates | $3,000,000 | Not provided |
| Manatt | $6,000,000 | Not provided |
| McDermott Will & Schulte | $11,000,000 | Confirmed May 2026 incident affecting personal data. |
| Phelps | $575,000 | Not provided |
| Proskauer Rose | $8,000,000 | Not provided |
| Rivkin Radler | $700,000 | Not provided |
| Squire Patton Boggs | $20,000,000 | Not provided |
| Taft | $6,000,000 | Confirmed March 2026 breach involving Social Security numbers. |
| Weil | $19,000,000 | Confirmed attack; ransom payment unverified. |
| White & Case | $30,000,000 | Not provided |
| WilmerHale | $17,000,000 | Confirmed May 2026 data breach. |
| Total Reported | $206,950,000 |
Silent Ransom Group, also tracked as Luna Moth and UNC3753, emerged after Conti shut down in 2022. Despite its ransomware label, it does not need to lock files.
Operators trick employees into granting access, steal documents, and threaten to publish them. Law firms have been a major focus because they hold private client information.
CybersecurityNews previously covered the group’s IT support impersonation attacks against law firms. Attackers call employees, pose as internal support staff, and persuade them to grant remote access. Legitimate software helps the activity blend into routine work, reducing reliance on malware that security tools might otherwise detect.
Related reporting on Luna Moth’s fake helpdesk domains describes websites designed to resemble company support services. Once they gain access, tools such as WinSCP and Rclone can transfer stolen files. The pressure comes from the possible disclosure of confidential records, not a sudden loss of access to business systems.
Crystal found instructions to use fresh wallets, keep victim funds separate, and avoid combining payouts. Operators sometimes broke those rules, linking transactions investigators could trace.
Smaller payments also reached regulated exchanges, creating potential leads through customer identity records. The analysis describes cash conversion through instant exchangers, couriers, and a Bitcoin-to-Zelle service.
For defenders, the attack chain makes identity checks essential. Employees should verify support requests through known internal channels before granting access.
Organizations should restrict remote access, deploy phishing-resistant authentication, and train staff to recognize phone-based deception. Working systems don’t prove sensitive files stay safe.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.