Google and the FBI warn ransomware gangs that impersonate IT personnel to break into homes and steal data.
TechCrunch
5h ago
Ai Focus
Google and the FBI say that Silent Ransom Group impersonated IT support to enter victim companies' offices and steal data, further escalating its extortion tactics against law firms.
Helpful
No.Help

Google and the FBI have warned that a ransomware group called the Silent Ransom Group is escalating its attacks on U.S. law firms. In addition to common phishing emails and social engineering, the group has, in some cases, sent people posing as IT support staff to enter victims' offices, directly access computers, and steal data.

The attack escalated from remote deception to in-person contact.

In a recent report, Google's Mandiant and Google Threat Intelligence Group stated that between January and May of this year, the group launched attacks against dozens of victims, using methods including obtaining access through "offline, face-to-face contact."

The FBI also issued an alert last month stating that the group impersonates corporate IT support personnel, guiding employees to cooperate via phone calls and emails. In some cases, the imposters even entered offices, accessed employee devices, and used USB storage devices or remote access tools to transfer data.

The target data includes contracts, taxes, and personal information.

According to disclosures by Google and the FBI, the stolen information included personally identifiable information such as contract documents and Social Security numbers, as well as financial and tax records. This data was subsequently used for blackmail.

Unlike traditional ransomware, this type of attack does not necessarily encrypt the victim's system. A more common tactic used by this group is to steal data first, then threaten to publicly disclose it and demand payment from the victim.

  • Attack period: January to May 2026
  • Primary targets: US law firms and other institutions
  • Common methods: impersonating IT support, screen sharing, USB theft, remote takeover

Theft is carried out after establishing trust through "security concerns".

Google says attackers typically contact employees under the guise of handling security incidents or assisting with corporate data migration, then lure them into joining screen-sharing sessions. The attackers then persuade victims to download and open screen-sharing software, or directly exploit built-in features in applications such as Zoom and Microsoft Teams to gain control.

Google stated that these cases demonstrate that some hackers are combining traditional cyberattacks with real-world physical contact, further increasing the difficulty for businesses to protect themselves. The risks of such impersonation attacks are particularly pronounced for organizations that rely on external IT support and have weak internal verification processes.

Tip
$0
Like
0
Save
0
Views 868
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Bitcoin fell below $60,000 after strong US jobs data.
Bitcoin fell below $60,000 after the release of US employment data, triggering a large-scale liquidation of long positions and putting pressure on derivatives and on-chain metrics.
Coinpaper
·2026-06-06 02:38:28
917
The Five Eyes alliance warns Chinese intelligence personnel to use LinkedIn to contact Westerners.
The Five Eyes intelligence alliance issued a joint warning, stating that Chinese intelligence personnel are using recruitment platforms such as LinkedIn to contact Western individuals and collect sensitive information.
TechCrunch
·2026-06-04 23:08:13
263
Foreign media: Bloomberg analysts warn of Bitcoin pullback risk
Bloomberg analyst Mike McGlone believes that Bitcoin has shown signs of weakness after breaking through $100,000, and if it fails to regain its lead over risk assets, the pressure for a pullback may increase.
CoinPedia
·2026-06-01 18:33:53
658
AI discovers old vulnerability in Zcash; security experts warn of risks to banking software.
After AI helped discover an old vulnerability in Zcash, industry insiders warned that similar flaws may exist in more crypto projects and banking systems, bringing formal verification back into focus.
CoinDesk
·2026-06-06 02:08:56
676
Foreign media: UK regulators warn of risks associated with encrypted partnerships among Premier League clubs.
British regulators have warned Premier League clubs to be cautious about working with unauthorized crypto companies, reflecting stricter regulations on crypto marketing and customer acquisition.
AMBCrypto
·2026-06-04 13:26:53
739