Leaked Chat Logs Show Silent Ransomware Extorted Over $200,000,000 in Six Months Without Encrypting Data | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files.

The reported earnings point to the power of data extortion, where attackers steal sensitive records and demand payment to keep them private. However, the payment figures remain unverified, and the group denies breaching its systems or leaking its chats.

DataBreaches reported the alleged leak on October 7. The material contains 5,692 messages covering August 27, 2025, through September 29, 2026.

Discussions reportedly include victim negotiations, payments, access methods, and members’ spending. An October 8 update said Silent Ransom Group had agreed to an interview but disputed the leak’s origin.

Silent Ransomware Extorted Over $200,000,000

The chats mark completed deals as “GOLD.” Adding those entries produces the $206.95 million total. Crystal Intelligence dates the 27 claimed payments between April 3 and September 24, 2026, placing the reported earnings within a period of less than six months. These entries reflect the criminals’ own records, not audited financial results.

According to DataBreaches, the median alleged payment was $6 million, while individual amounts ranged from $100,000 to $30 million. White & Case was listed against the largest amount. Nine named firms disclosed breaches relevant to the period. However, those disclosures do not confirm who attacked them or whether they paid the sums shown.

Crystal Intelligence’s blockchain analysis found transactions matching the timing of several chat entries. One upstream collection wallet received about 344 bitcoin, valued at roughly $27 million, over six weeks.

Researchers could not connect individual victim payments to that wallet. Hence, the evidence supports substantial money movement rather than proving the headline total.

Payments by 27 Victims Named in Leaked Chats :

Law FirmReported PaymentBreach Confirmation
Beveridge & Diamond$1,000,000Not provided
Blank Rome$17,500,000Confirmed May 2026 breach; attorney tricked into uploading files to Google Drive.
Bowman and Brooke$100,000Not provided
Buchalter$10,000,000Confirmed August 2026 data breach involving client and patient information.
Chartwell$1,000,000Confirmed April 2026 social-engineering incident.
Cox Castle$600,000Not provided
Dentons$21,000,000Not provided
Dickie, McCamey & Chilcote$450,000Not provided
F3 Law$400,000Not provided
Fragomen$10,500,000Confirmed May 2026 account compromise.
Goodwin Procter$10,000,000Confirmed employee credential theft in spring 2026.
Goulston & Storrs$450,0002026 data breach involving driver’s licenses.
Gray Reed$500,000Not provided
Hinshaw & Culbertson$8,000,000Not provided
Irell & Manella$275,000Not provided
Jackson Lewis$3,900,000Not provided
K&L Gates$3,000,000Not provided
Manatt$6,000,000Not provided
McDermott Will & Schulte$11,000,000Confirmed May 2026 incident affecting personal data.
Phelps$575,000Not provided
Proskauer Rose$8,000,000Not provided
Rivkin Radler$700,000Not provided
Squire Patton Boggs$20,000,000Not provided
Taft$6,000,000Confirmed March 2026 breach involving Social Security numbers.
Weil$19,000,000Confirmed attack; ransom payment unverified.
White & Case$30,000,000Not provided
WilmerHale$17,000,000Confirmed May 2026 data breach.
Total Reported$206,950,000

Silent Ransom Group, also tracked as Luna Moth and UNC3753, emerged after Conti shut down in 2022. Despite its ransomware label, it does not need to lock files.

Operators trick employees into granting access, steal documents, and threaten to publish them. Law firms have been a major focus because they hold private client information.

CybersecurityNews previously covered the group’s IT support impersonation attacks against law firms. Attackers call employees, pose as internal support staff, and persuade them to grant remote access. Legitimate software helps the activity blend into routine work, reducing reliance on malware that security tools might otherwise detect.

Related reporting on Luna Moth’s fake helpdesk domains describes websites designed to resemble company support services. Once they gain access, tools such as WinSCP and Rclone can transfer stolen files. The pressure comes from the possible disclosure of confidential records, not a sudden loss of access to business systems.

Crystal found instructions to use fresh wallets, keep victim funds separate, and avoid combining payouts. Operators sometimes broke those rules, linking transactions investigators could trace.

Smaller payments also reached regulated exchanges, creating potential leads through customer identity records. The analysis describes cash conversion through instant exchangers, couriers, and a Bitcoin-to-Zelle service.

For defenders, the attack chain makes identity checks essential. Employees should verify support requests through known internal channels before granting access.

Organizations should restrict remote access, deploy phishing-resistant authentication, and train staff to recognize phone-based deception. Working systems don’t prove sensitive files stay safe.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

——————————————————–


Click Here For The Original Source.

.........................