Leaked Chat Logs Show Silent Ransomware Extorted Over $200,000,000 in 6 Months Without Encrypting Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files.

The reported earnings point to the power of data extortion, where attackers steal sensitive records and demand payment to keep them private. However, the payment figures remain unverified, and the group denies breaching its systems or leaking its chats.

DataBreaches reported the alleged leak on October 7. The material contains 5,692 messages covering August 27, 2025, through September 29, 2026.

Discussions reportedly include victim negotiations, payments, access methods, and members’ spending. An October 8 update said Silent Ransom Group had agreed to an interview but disputed the leak’s origin.

Silent Ransomware Extorted Over $200,000,000

The chats mark completed deals as “GOLD.” Adding those entries produces the $206.95 million total. Crystal Intelligence dates the 27 claimed payments between April 3 and September 24, 2026, placing the reported earnings within a period of less than six months. These entries reflect the criminals’ own records, not audited financial results.

According to DataBreaches, the median alleged payment was $6 million, while individual amounts ranged from $100,000 to $30 million. White & Case was listed against the largest amount. Nine named firms disclosed breaches relevant to the period. However, those disclosures do not confirm who attacked them or whether they paid the sums shown.

Crystal Intelligence’s blockchain analysis found transactions matching the timing of several chat entries. One upstream collection wallet received about 344 bitcoin, valued at roughly $27 million, over six weeks.

Researchers could not connect individual victim payments to that wallet. Hence, the evidence supports substantial money movement rather than proving the headline total.

Payments by 27 Victims Named in Leaked Chats :

Law Firm Reported Payment Breach Confirmation
Beveridge & Diamond $1,000,000 Not provided
Blank Rome $17,500,000 Confirmed May 2026 breach; attorney tricked into uploading files to Google Drive.
Bowman and Brooke $100,000 Not provided
Buchalter $10,000,000 Confirmed August 2026 data breach involving client and patient information.
Chartwell $1,000,000 Confirmed April 2026 social-engineering incident.
Cox Castle $600,000 Not provided
Dentons $21,000,000 Not provided
Dickie, McCamey & Chilcote $450,000 Not provided
F3 Law $400,000 Not provided
Fragomen $10,500,000 Confirmed May 2026 account compromise.
Goodwin Procter $10,000,000 Confirmed employee credential theft in spring 2026.
Goulston & Storrs $450,000 2026 data breach involving driver’s licenses.
Gray Reed $500,000 Not provided
Hinshaw & Culbertson $8,000,000 Not provided
Irell & Manella $275,000 Not provided
Jackson Lewis $3,900,000 Not provided
K&L Gates $3,000,000 Not provided
Manatt $6,000,000 Not provided
McDermott Will & Schulte $11,000,000 Confirmed May 2026 incident affecting personal data.
Phelps $575,000 Not provided
Proskauer Rose $8,000,000 Not provided
Rivkin Radler $700,000 Not provided
Squire Patton Boggs $20,000,000 Not provided
Taft $6,000,000 Confirmed March 2026 breach involving Social Security numbers.
Weil $19,000,000 Confirmed attack; ransom payment unverified.
White & Case $30,000,000 Not provided
WilmerHale $17,000,000 Confirmed May 2026 data breach.
Total Reported $206,950,000

Silent Ransom Group, also tracked as Luna Moth and UNC3753, emerged after Conti shut down in 2022. Despite its ransomware label, it does not need to lock files.

Operators trick employees into granting access, steal documents, and threaten to publish them. Law firms have been a major focus because they hold private client information.

CybersecurityNews previously covered the group’s IT support impersonation attacks against law firms. Attackers call employees, pose as internal support staff, and persuade them to grant remote access. Legitimate software helps the activity blend into routine work, reducing reliance on malware that security tools might otherwise detect.

Related reporting on Luna Moth’s fake helpdesk domains describes websites designed to resemble company support services. Once they gain access, tools such as WinSCP and Rclone can transfer stolen files. The pressure comes from the possible disclosure of confidential records, not a sudden loss of access to business systems.

Crystal found instructions to use fresh wallets, keep victim funds separate, and avoid combining payouts. Operators sometimes broke those rules, linking transactions investigators could trace.

Smaller payments also reached regulated exchanges, creating potential leads through customer identity records. The analysis describes cash conversion through instant exchangers, couriers, and a Bitcoin-to-Zelle service.

For defenders, the attack chain makes identity checks essential. Employees should verify support requests through known internal channels before granting access.

Organizations should restrict remote access, deploy phishing-resistant authentication, and train staff to recognize phone-based deception. Working systems don’t prove sensitive files stay safe.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Leaked Chat Logs Show Silent Ransomware Extorted Over $200,000,000 in 6 Months Without Encrypting Data appeared first on Cyber Security News.