Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months, and they did it without encrypting a single victim's files. If the figures are accurate, they show how profitable data extortion without encryption ransomware can be: attackers steal sensitive records, then demand payment to keep them from being published or sold.
The story matters beyond the 27 companies named in the reporting. Behind every stolen database are people whose personal details now sit in criminal hands, whether or not the company paid.
How Silent Ransom Group's Extortion Works Without Encryption
Traditional ransomware locks files and demands payment for a decryption key. Many groups later added a second step, stealing data first so they could threaten to leak it if the victim restored from backups. That approach is often called double extortion.
The activity described in the leaked chats skips the lock-up stage. According to the reporting, the group did not encrypt victims' files at all. Instead, the leverage came entirely from stolen data and the threat of exposing it.
There are practical reasons this appeals to criminals. Encryption is noisy: it can crash systems, trigger security alerts and give defenders a clear moment to respond. Quietly copying records is harder to spot. It also means a victim cannot solve the problem by restoring from backups, because the threat is not lost access. The threat is that the data will go public.
The core lesson from the reported numbers is simple. Stolen data alone can be enough pressure to produce enormous payouts.
Why Stolen Records Put Individuals at Risk
When a company is extorted over stolen files, the people in those files rarely get a say. Customer, employee and patient records can contain names, contact details, account information and other sensitive material. The source article does not specify which data types were taken from the 27 firms, so it is worth being careful here: the risk depends on what each victim held.
In general, though, stolen records fuel a predictable set of problems:
- Phishing: Criminals can craft convincing messages that reference real details about you or your relationship with a company.
- Fraud and identity misuse: Personal information can be combined with other leaked data to open accounts or take over existing ones.
- Repeat exposure: Paying a ransom does not guarantee deletion. Data that has been copied once can be copied again or resold.
That last point is important. Even when a company pays, individuals have little way to verify what happened to their information. Exposed databases show how quickly records can spread. The Tribeca Film Festival database leak, which involved more than 666,000 records, is a different kind of incident, but it illustrates how exposed personal data becomes a lasting problem for the people in it.
What the Leaked Chats Do and Don't Prove
A measured reading is essential here. The chats are described as alleged internal communications, and the $206.95 million figure comes from those chats. The source summary does not describe independent verification of the total, the number of victims or the payments themselves.
Criminals can exaggerate, and leaked logs can be incomplete or taken out of context. So the figures are best treated as claims that fit a broader pattern, not as audited totals.
What the leak does support is the direction of travel. Extortion built on stolen data is a workable business model without any encryption involved. Leaked communications have also reshaped the ransomware world before. The Gunra ransomware group built its code on material derived from the leaked Conti source, and Conti itself was undone in part by exposed internal chats. Leaks like these give researchers and defenders a rare look at how criminal groups operate and what they earn.
What This Means For You
You probably cannot stop a company you do business with from being breached. You can limit how much damage stolen data does to you. Assume that any organization holding your information could one day lose it, and prepare accordingly.
If your details are exposed, the most likely follow-up is not a dramatic hack but a convincing message, call or login attempt using real information about you. That makes habits more valuable than any single tool.
Steps to Protect Yourself After a Data Theft
- Check whether your data has leaked. Use a reputable breach-notification service to see if your email address or phone number appears in known leaks, and read any notice a company sends you.
- Tighten credential hygiene. Use a unique password for every account, store them in a password manager, and turn on multi-factor authentication, preferably with an app or hardware key rather than SMS.
- Treat unexpected messages with suspicion. If a message mentions a recent breach or asks you to act urgently, go to the company's official site directly instead of clicking links.
- Consider a credit freeze. If financial or identity details may be involved, freezing your credit makes it harder for someone to open accounts in your name.
- Opt out of data brokers. The less personal information is available for sale, the less material criminals have to build convincing scams.
- Monitor your accounts. Watch bank statements and account activity for anything unfamiliar, and report it quickly.
The Bottom Line
The alleged Silent Ransom Group chats, with their claimed $206.95 million from 27 firms, are a reminder that data extortion without encryption ransomware does not need locked screens to work. Even if the exact numbers are disputed, the model is clear: steal data, then sell silence.
You cannot control how well others protect your records, but you can control your response. Check whether your data has appeared in a leak, strengthen your passwords and authentication, and opt out of data brokers. Reading about incidents like the Tribeca Film Festival leak and the Gunra RaaS expansion helps show how widely exposed data and criminal ecosystems connect, and why a few minutes of preparation now is worth it.




