Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files.
The reported earnings point to the power of data extortion, where attackers steal sensitive records and demand payment to keep them private. However, the payment figures remain unverified, and the group denies breaching its systems or leaking its chats.
DataBreaches reported the alleged leak on October 7. The material contains 5,692 messages covering August 27, 2025, through September 29, 2026.
Discussions reportedly include victim negotiations, payments, access methods, and members’ spending. An October 8 update said Silent Ransom Group had agreed to an interview but disputed the leak’s origin.
Silent Ransomware Extorted Over $200,000,000
The chats mark completed deals as “GOLD.” Adding those entries produces the $206.95 million total. Crystal Intelligence dates the 27 claimed payments between April 3 and September 24, 2026, placing the reported earnings within a period of less than six months. These entries reflect the criminals’ own records, not audited financial results.
According to DataBreaches, the median alleged payment was $6 million, while individual amounts ranged from $100,000 to $30 million. White & Case was listed against the largest amount. Nine named firms disclosed breaches relevant to the period. However, those disclosures do not confirm who attacked them or whether they paid the sums shown.
Crystal Intelligence’s blockchain analysis found transactions matching the timing of several chat entries. One upstream collection wallet received about 344 bitcoin, valued at roughly $27 million, over six weeks.
Researchers could not connect individual victim payments to that wallet. Hence, the evidence supports substantial money movement rather than proving the headline total.
Payments by 27 Victims Named in Leaked Chats :
| Law Firm | Reported Payment | Breach Confirmation |
|---|---|---|
| Beveridge & Diamond | $1,000,000 | Not provided |
| Blank Rome | $17,500,000 | Confirmed May 2026 breach; attorney tricked into uploading files to Google Drive. |
| Bowman and Brooke | $100,000 | Not provided |
| Buchalter | $10,000,000 | Confirmed August 2026 data breach involving client and patient information. |
| Chartwell | $1,000,000 | Confirmed April 2026 social-engineering incident. |
| Cox Castle | $600,000 | Not provided |
| Dentons | $21,000,000 | Not provided |
| Dickie, McCamey & Chilcote | $450,000 | Not provided |
| F3 Law | $400,000 | Not provided |
| Fragomen | $10,500,000 | Confirmed May 2026 account compromise. |
| Goodwin Procter | $10,000,000 | Confirmed employee credential theft in spring 2026. |
| Goulston & Storrs | $450,000 | 2026 data breach involving driver’s licenses. |
| Gray Reed | $500,000 | Not provided |
| Hinshaw & Culbertson | $8,000,000 | Not provided |
| Irell & Manella | $275,000 | Not provided |
| Jackson Lewis | $3,900,000 | Not provided |
| K&L Gates | $3,000,000 | Not provided |
| Manatt | $6,000,000 | Not provided |
| McDermott Will & Schulte | $11,000,000 | Confirmed May 2026 incident affecting personal data. |
| Phelps | $575,000 | Not provided |
| Proskauer Rose | $8,000,000 | Not provided |
| Rivkin Radler | $700,000 | Not provided |
| Squire Patton Boggs | $20,000,000 | Not provided |
| Taft | $6,000,000 | Confirmed March 2026 breach involving Social Security numbers. |
| Weil | $19,000,000 | Confirmed attack; ransom payment unverified. |
| White & Case | $30,000,000 | Not provided |
| WilmerHale | $17,000,000 | Confirmed May 2026 data breach. |
| Total Reported | $206,950,000 |
Silent Ransom Group, also tracked as Luna Moth and UNC3753, emerged after Conti shut down in 2022. Despite its ransomware label, it does not need to lock files.
Operators trick employees into granting access, steal documents, and threaten to publish them. Law firms have been a major focus because they hold private client information.
CybersecurityNews previously covered the group’s IT support impersonation attacks against law firms. Attackers call employees, pose as internal support staff, and persuade them to grant remote access. Legitimate software helps the activity blend into routine work, reducing reliance on malware that security tools might otherwise detect.
Related reporting on Luna Moth’s fake helpdesk domains describes websites designed to resemble company support services. Once they gain access, tools such as WinSCP and Rclone can transfer stolen files. The pressure comes from the possible disclosure of confidential records, not a sudden loss of access to business systems.
Crystal found instructions to use fresh wallets, keep victim funds separate, and avoid combining payouts. Operators sometimes broke those rules, linking transactions investigators could trace.
Smaller payments also reached regulated exchanges, creating potential leads through customer identity records. The analysis describes cash conversion through instant exchangers, couriers, and a Bitcoin-to-Zelle service.
For defenders, the attack chain makes identity checks essential. Employees should verify support requests through known internal channels before granting access.
Organizations should restrict remote access, deploy phishing-resistant authentication, and train staff to recognize phone-based deception. Working systems don’t prove sensitive files stay safe.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
