Silent Ransom Group leak claims $207M extorted from 27 law firms

According to Security Affairs, citing a report by DataBreaches, leaked internal chats from the Silent Ransom Group suggest the crew extorted about $207 million from 27 law firms in roughly six months without encrypting any files. The figures come from the group’s own records and have not been confirmed by the victims; blockchain analysis supports the scale but not the exact amounts.

What we know

  • DataBreaches reports that researcher Tammy Harper shared the leak with it as an onion site holding 5,692 chat messages.
  • The data comes from two of the group’s servers and covers about 13 months, from August 2025 to September 2026.
  • The chats cover ransom negotiations, ways to access victim systems, plans for future targets and victim payments, along with personal topics.
  • The group’s internal deal board claims about $207 million was paid by 27 firms between April 3 and September 24, 2026.
  • Crystal Intelligence examined the cryptocurrency flows and concluded the on-chain evidence supports the scale but not the exact figures.

Per the report, the group does not rely on encryption. There is no malware payload and no locked files: the approach is phone calls and social engineering aimed almost entirely at law firms.

How much was paid, and how it was cashed out

The median payment across the 27 firms was $6 million, and the mean was about $7.66 million, pulled up by a few very large outliers. The largest single payment was reportedly $30 million from White & Case, which one group leader celebrated in the chats at about 31.25 million after Bitcoin’s price moved. White & Case’s own position is not stated in the source material we reviewed, so treat the attribution as a claim from the leaked chats.

Crystal Intelligence describes a cash-out chain of instant exchangers, a cash courier in Moscow, a Bitcoin-to-Zelle desk and a coin-mixing wallet used when funds were flagged as suspicious. The operators had wallet rules meant to defeat tracing but did not always follow them. Many smaller payments reportedly went straight to regulated exchanges where accounts are tied to verified identities, which the report calls the network’s weakest point.

Who is affected

The victims named in the reporting are law firms, which hold privileged client communications and sensitive deal and litigation data. Which firms paid, apart from the single payment above, and what data was accessed, has not been disclosed in the material we reviewed. How the group gains its initial access is described only as phone calls and social engineering; no technical details such as vulnerabilities or tools were provided.

What has not been confirmed

  • The $207 million total and the count of 27 firms are the group’s own claims; on-chain data does not confirm the exact amounts.
  • The authenticity of the leak is based on the reporting by DataBreaches and Security Affairs; the victims have not publicly confirmed payments in the sources we have.
  • No indicators of compromise, such as phone numbers, domains or wallet addresses, are available to us, so none are listed here.

Why this matters

Analysis, not new facts. If the reporting is accurate, an attack with no malware gives endpoint tooling little to detect. The control that matters is the human one: help desk and staff verification. Law firms, and any organisation that holds client confidential data, should assume that a convincing caller claiming to be IT support or a vendor is a realistic entry path. The leak also shows that regulated exchanges are a point where payments can be traced, which may help investigators and incident responders.

What to do

  1. Brief staff and the help desk that attackers are using phone calls and social engineering, and require call-back verification through a known number before granting remote access or resetting credentials.
  2. Restrict and log remote-access and remote-support tools; alert on new tools or sessions started after an unsolicited phone call.
  3. Hunt for unusual bulk data access or exfiltration from file servers and document management systems, since the extortion here does not depend on encryption.
  4. Rehearse your response to a pure data-theft extortion demand: involve legal counsel, law enforcement and your cyber insurer before any contact or payment.
  5. Law firms should check client notification obligations and prepare how to tell clients if their data is at risk.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.