Ransomware has changed shape. Where early attacks relied on encrypting files and demanding payment for a decryption key, a group known as the Silent Ransom Group has built its playbook around a different goal: stealing sensitive data and threatening to expose it. The tactic, often called extortion-only ransomware, skips encryption entirely and instead pressures victims with the fear of public leaks. Now the group has taken that strategy a step further, deploying fake IT workers who show up in person to gain access to victim organizations.
From Encryption to Extortion: The Evolution of Ransomware Tactics
The reason for this shift is practical. Widespread adoption of reliable backup systems and the growing availability of free decryption tools have made traditional encryption-based ransomware less effective. If a victim can simply restore their data from a backup, there is no incentive to pay a ransom for a decryption key. Extortion-focused groups have adapted by cutting encryption out of the equation altogether. Instead, they quietly copy sensitive files, then threaten to release or sell that data unless the victim pays up.
This approach requires attackers to get creative about how they gain access in the first place, since there is no malware payload doing the heavy lifting. That is where social engineering, and now physical presence, come into play.
Fake IT Workers and In-Person Intrusions
According to a warning issued by the FBI, Silent Ransom Group, also tracked under the names Luna Moth, Chatty Spider, and UNC3753, has been targeting law firms using a combination of phishing emails and impersonation of IT support personnel. Rather than relying solely on remote attacks, operators associated with the group have reportedly shown up in person at targeted offices, posing as IT technicians to gain physical access to networks and systems.
Security researchers tracking the campaign, including analysts at Mandiant, identified a wave of these financially motivated data theft operations against U.S. law firms earlier this year. The pattern reflects a broader trend across the ransomware ecosystem, where threat actors increasingly blend digital and physical tactics to bypass technical defenses that have gotten harder to crack from the outside. It echoes a pattern seen elsewhere in the ransomware world, where groups pivot quickly once a vulnerability or technique proves effective, a dynamic also visible in ongoing exploitation of the BlueHammer flaw by ransomware gangs.
Why Law Firms and Privacy Are at Risk
Law firms make attractive targets for exactly the reasons that make extortion-only ransomware effective. They hold enormous volumes of confidential client information, from litigation records to financial documents and personal data covered by attorney-client privilege. A breach at a firm does not just expose the organization itself; it puts every client whose information passes through that firm at risk of having sensitive details leaked or sold.
The use of fake IT workers adds another layer of concern. Employees are trained to be wary of suspicious emails or links, but far fewer organizations have robust protocols for verifying the identity of someone claiming to be IT support who walks in the door. Once inside, an impersonator can gain direct access to workstations, servers, or credentials that would otherwise require a technical exploit to reach remotely. That access can then be used to exfiltrate data quietly, long before anyone realizes something is wrong.
What This Means For You
Even if you do not work at a law firm, this shift matters. It signals that attackers are willing to invest time and effort into physical reconnaissance and impersonation when digital defenses become too strong. Any organization handling sensitive personal or financial data, including healthcare providers, financial institutions, and government contractors, could become a future target using the same playbook.
For individuals, the takeaway is about awareness. Data you share with any professional service, whether a lawyer, accountant, or healthcare provider, is only as secure as that organization's weakest link, which increasingly includes its front-door verification process, not just its firewalls.
Actionable Takeaways
- Ask service providers handling your sensitive data, such as law firms or financial advisors, whether they have identity verification procedures for in-person IT visits.
- Be cautious about how much personal information you share with any organization, and ask how long they retain it.
- If you receive notice of a data breach involving a professional service you use, monitor your accounts and credit reports for suspicious activity.
- Organizations should train staff to verify the identity of anyone claiming to be IT personnel, whether the contact comes by phone, email, or in person.
The Silent Ransom Group's pivot toward fake IT workers is a reminder that ransomware defense is no longer just a technical problem. As extortion tactics evolve, so must the human processes designed to stop them.




