SILENT Ransom Group reportedly extorted about $207 million from 27 law firms in six months by using phone calls and social engineering rather than encrypting files. The group’s technique relies on manipulating victims and their staff into handing over access or documents, with no malware or encrypted data involved.
A leak of internal chats, first shared with DataBreaches by researcher Tammy Harper, contains about 5,692 messages dated from August 2025 to September 2026 that discuss ransom negotiations, access methods, and targets, including discussions of firearms and even an apartment purchase in Moscow. The communications portray a sales-like approach to crime, rather than a strictly technical operation.
Evidence compiled by Crystal Intelligence suggests on-chain activity supports the scale of the operation but does not confirm exact totals. The group’s records claim that 27 firms paid around $207 million between 3 April and 24 September 2026, with a median payment of about $6 million and a largest payment of $30 million from White & Case.
Payouts allegedly used a mix of instant exchangers, a Moscow cash courier, a Bitcoin-to‑Zelle desk, and coin-mixing wallets to evade tracing, though smaller payments sometimes went to regulated exchanges where accounts are tied to verified identities—the report notes this as a potential vulnerability in the network. Some firms’ alleged offers and responses in the chat logs are not corroborated by public disclosures, and some claims remain disputed.
The case underscores that serious profits can be pursued without malware, highlighting the need for heightened security training and vigilance against social engineering in law firms. A follow-up from DataBreaches on 9 October 2026 challenges the group’s denial of a breach, leaving the situation unresolved.