Leaked Chats Show a Russian Extortion Gang Sending Fake IT Workers Into US Law Firms to Copy Files by Hand
A leak of thousands of internal chats from the Silent Ransom Group shows how the Russia-linked crew recruited in-person agents to pose as IT staff at US law firms, ran victims through a sales pipeline and claimed about $200 million in settlements.

Someone walked into a New York law firm's office and copied its files onto a flash drive. The firm later told the extortionists holding those files that it knew exactly how they got them. That exchange sits in a newly leaked archive of chats from a Russia-linked crew that recruits "agents" to pose as IT staff inside US law firms.
The crew is the Silent Ransom Group, also tracked as Luna Moth and Chatty Spider. In early October, an unidentified source with no stated motive posted thousands of its internal messages, running from August 2025 to September 2026, to a purpose-built .onion site. Recorded Future News reviewed the archive, which has been dubbed the "Luna Moth Files."
The leak looks real. Chainalysis matched crypto addresses in it to known SRG extortions, including a $10 million payment from a victim in mid-2026, Silicon reports. The firm cautioned that it cannot "speak to the totality of claims."
No encryption, just theft
SRG emerged in March 2022 from the collapse of Conti, the ransomware empire whose members are still being sentenced in US courts. Unlike Conti, it skips encryption entirely. It talks its way into big law firms with phone calls and phishing, uses legitimate remote management software to get inside, steals data and demands payment not to publish it.
When that fails, it sends people. In late May, the FBI warned that operatives were showing up posing as a firm's own tech support and plugging storage devices into computers.
The chats fill in that picture. In one negotiation, a law firm said it knew someone had entered its New York office and copied files to a flash drive. Its executives had authorized $1 million, but wanted proof that every copy was destroyed. They pointed to LockBit, which failed to delete data from victims who paid.
Pizza bags, masks and fake IDs
Members brainstormed ways to get agents through the door. One idea was a pizza delivery ruse: "We buy these insulated bags and uniforms for agents." Others included custom masks modelled on real lawyers and smart glasses for an agent posing as a client. The group discussed a $3,200 UV printer and holographic material for fake IDs, and paid forgers, including one in New York. Nothing in the archive shows the pizza ruse or the masks were ever used.
Agents came from paid Telegram ads aimed at Russian speakers and disguised as nightclub promotion, courier work and security jobs. A roster listed agents by number and city. One was a 17-year-old, flagged as underage. A channel name suggests one agent was caught in Chicago.
The apparent leader put the usable rate at about one in 10 and called it "conversion."
A sales pipeline for extortion
Victims moved through stages the gang labelled "chat," "offer," "contract" and "gold." One $100,000 opening offer was mocked as "missing a zero." That negotiation climbed through $500,000, $1.5 million, $2.25 million, $3 million and $3.5 million before landing on a $6 million contract and "gold."
About 50 organizations appear in the chats, most of them law firms. The gang's own figures add up to roughly $200 million in settlements, a number nobody has verified. Researchers estimate that more than 100 law firms have had data stolen by the group overall.
Darker talk
The chats also contain plans far beyond data theft, with no evidence any were carried out. Members talked about following senior lawyers they called "oldies," photographing a target's school-age child as leverage, running a fake escort site for sexual blackmail, kidnapping executives and setting up a "punishment" group.
In April, the leader floated targeting a senior employee at a major US Army contractor. Another member suggested, with a laughing emoticon, that the Russian Ministry of Defense could pay. There is no evidence it ever did. A channel in May discussed recruiting US sailors near naval bases for information on "submarine-based nuclear forces."
By September, when the archive ends, the group was talking about relaunching as Sleepless Threat. A senior member had spelled out the ambition back in April: "The ultimate goal is to become a social movement or a cult."
Some offers on this page may be paid placements or contain affiliate links.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free