<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Silent Ransom Group Now Sending Fake IT Staff to Physically Breach Law Firms

SRG targets US law firms with sophisticated scams, impersonating IT to gain access. FBI advises strict verification and training.
Content Team

A cybercriminal group called Silent Ransom Group (SRG) has escalated its attacks on US law firms by impersonating IT staff — both over the phone and in person. Since 2023, the group has targeted law, insurance, finance, and healthcare firms using callback scams to trick employees into granting remote desktop access.

As of spring 2026, the FBI warns that when remote access fails, SRG sends an actor physically to the victim's office, convincing staff to plug in an external drive under the guise of IT maintenance. Data is then quietly exfiltrated using legitimate tools like WinSCP or Rclone — making traditional antivirus detection unlikely.

The FBI recommends verifying all visitor credentials, disabling external drive permissions, enforcing phishing-resistant MFA, and training staff to authenticate IT requests before granting any access.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo