logo

Extortion crews are visiting law firms pretending to be tech support, FBI warns

ID: 672029f6-48b9-50fe-89ad-ea16d7a447b9

STIX ID: report--672029f6-48b9-50fe-89ad-ea16d7a447b9

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

The FBI warns that the Silent Ransom Group (SRG) has been targeting US law firms since 2022 using callback phishing to impersonate IT staff, obtain remote access, and exfiltrate sensitive files; when phishing fails, attackers have reportedly physically entered offices to plug thumb drives into machines and copy data for extortion via a data-leak site. The advisory details SRG tactics (phone impersonation, remote desktop access, use of WinSCP/Rclone, DLS extortion), cites recent Spring 2026 activity and alleged victims, and recommends mitigations such as blocking external drives, enforcing phishing-resistant MFA, restricting access to sensitive data, blocking port 22, and robust staff training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.