Security News

Leaked Chats Reveal Extortion Gang Sending 'Agents' Into US Law Firms

The Record · 9 Oct 2026
Key Takeaway Verify the identity of anyone claiming to be IT support before giving them access to your office or devices, because cyber criminals can also attack in person.

Leaked chat logs reviewed by Recorded Future News show a Russia-based cyberextortion gang planning to send operatives into US law firms, along with other extreme schemes such as kidnapping executives and recruiting military personnel. The archive, posted to a dark web site in early October by an unidentified source, holds thousands of messages from August 2025 to September 2026. In them, members track dozens of victims, argue over multimillion-dollar payments and direct US-based operatives they call "agents". Some named organisations have not publicly acknowledged a breach.

The archive mixes real extortion records with brainstorming, abandoned plans, boasting and violent fantasies, and Recorded Future News could not verify whether the most extreme schemes were ever attempted. Parts of it have been corroborated, though. Chainalysis tied cryptocurrency addresses in the leak to known extortions by the Silent Ransom Group, also tracked as Luna Moth and Chatty Spider, while noting it could not speak to the totality of the claims. The FBI has also warned that the group's members posed as IT personnel to gain physical access to computers.

In one negotiation, a law firm's representative said the firm knew an individual had entered its New York office and copied files onto a flash drive. Executives had authorised $1 million to settle but wanted proof that all digital and physical copies would be destroyed, citing evidence that the LockBit ransomware gang had failed to delete data belonging to victims who paid.

extortion Silent Ransom Group social engineering law firms physical security

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.