# Silent Ransom Group: FBI Warns of In-Person Data Theft at Law Firms

> The FBI warns that Silent Ransom Group is conducting physical data theft attacks against US law firms using unauthorized building access and hardware.

- Published: 2026-05-27T13:21:33.000Z
- Severity: high
- Category: Threat Intel
- Tags: Silent Ransom Group, SRG, Law Firms, FBI Advisory, Physical Security
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/
- Canonical: https://runtimerebel.com/blog/silent-ransom-group-fbi-warns-of-in-person-data-theft-at-law-firms

## Key points

- Silent Ransom Group targets US law firms using physical access to corporate offices to exfiltrate sensitive legal data directly.
- The campaign affects Windows-based workstations and internal networks in legal offices with inadequate physical security controls.
- Implement multi-factor authentication for all remote access and strengthen physical perimeter controls including visitor logging and camera surveillance.

The Federal Bureau of Investigation (FBI) has issued a warning regarding a significant shift in [TTP](/glossary#ttp) employed by the extortion gang known as Silent Ransom Group (SRG), also identified as Luna Moth. According to [BleepingComputer](https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/), these attackers are now conducting in-person data theft operations against law firms across the United States. This tactical evolution indicates a move away from purely remote [Phishing](/glossary#phishing) or software exploitation toward physical compromise to bypass perimeter defenses.

## The Shift to In-Person Data Exfiltration

Unlike traditional [Ransomware](/glossary#ransomware) groups that rely on malicious attachments or credential harvesting, the Silent Ransom Group is reportedly sending operatives to physical office locations. These individuals attempt to gain unauthorized access to the premises, often by tailgating legitimate employees or utilizing social engineering techniques to deceive reception and security personnel. Once inside, the goal is to obtain direct access to the internal network.

Technicians or "field agents" for the group reportedly deploy hardware such as USB drives or small form-factor devices like Raspberry Pis to establish a [C2](/glossary#c2) channel. This allows the group to conduct [Lateral Movement](/glossary#lateral-movement) across the network while circumventing the [EDR](/glossary#edr) solutions that might typically flag suspicious inbound traffic from external IPs. Identifying **how to detect Silent Ransom Group physical intrusion** requires a focus on unexpected hardware changes and anomalies in internal traffic patterns that do not correlate with standard business hours.

### Targeting the Legal Sector

Law firms are particularly lucrative targets for this group due to the nature of the data they possess, including intellectual property, sensitive litigation strategies, and personally identifiable information (PII). By gaining physical access, the group can target specific high-value workstations belonging to partners or senior counsel. The FBI's warning suggests that the group is focused on data theft for extortion purposes rather than data encryption. This "silent" approach allows them to exfiltrate massive volumes of data before the [SOC](/glossary#soc) even identifies a breach.

## Silent Ransom Group Mitigation Steps for Law Firms

Defending against a threat that transitions from the digital to the physical realm requires a unified security posture. Organizations should audit their physical access control systems and ensure that all entry points are monitored and logged. Security awareness training should be updated to include scenarios involving "social engineering in the lobby," where attackers may pose as maintenance workers, delivery drivers, or IT contractors.

From a technical perspective, the [SIEM](/glossary#siem) should be configured to alert on any new device connections to the network that do not match the organization’s hardware whitelist. Implementing [Zero Trust](/glossary#zero-trust) principles is also a priority; even if an attacker manages to plug a device into a physical Ethernet port, they should be met with strict network access control (NAC) requirements that mandate device authentication and [Privilege Escalation](/glossary#privilege-escalation) prevention.

### Monitoring and Detection Strategies

To align with the [MITRE ATT&CK](/glossary#mitre-att-ck) framework, defenders should focus on the "Initial Access" and "Exfiltration" stages. The **FBI advisory on SRG extortion attacks** highlights the need for rigorous monitoring of outgoing traffic to known file-sharing services or unusual IP ranges. Because the group often uses legitimate remote desktop tools once they have established a foothold, security teams must monitor for the unauthorized installation of software like AnyDesk or TeamViewer.

In summary, the transition to physical data theft represents a calculated effort by SRG to stay ahead of automated security tools. Effective **Silent Ransom Group mitigation steps for law firms** must integrate physical perimeter defense with granular internal network monitoring to identify and neutralize the threat before data reaches external actors.

**Related:** [Physical Access Risks: FBI Warns of In-Person USB Attacks by SRG](/blog/physical-access-risks-fbi-warns-of-in-person-usb-attacks-by-srg), [YellowKey: Bypassing Windows 11 BitLocker TPM Protections](/blog/yellowkey-bypassing-windows-11-bitlocker-tpm-protections)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/silent-ransom-group-fbi-warns-of-in-person-data-theft-at-law-firms
