FBI Warns Law Firms as Extortion Gang Sends Operatives to Plug In USB Drives and Steal Client Data

The FBI warns that Silent Ransom Group operatives now walk into U.S. law firms posing as IT support to insert USB drives and steal sensitive client data for extortion when remote phishing fails. Fresh attacks in spring 2026 show the group's four-year campaign blending social engineering with physical access. Law firms must tighten visitor verification and disable unauthorized hardware connections to close this persistent vulnerability.
FBI Warns Law Firms as Extortion Gang Sends Operatives to Plug In USB Drives and Steal Client Data
Written by Maya Perez

The FBI has a blunt message for law firms across the United States. Know your IT guy. Because the one at your door might not work for you.

Cybercriminals from the Silent Ransom Group, active since 2022, have expanded their playbook. When callback phishing fails to deliver remote access, they dispatch people to walk into offices. These operatives pose as technical support. They claim a need to image a device or create a backup after a supposed phishing incident. Then they insert a USB drive or external hard drive and copy sensitive files.

The data taken isn’t for idle curiosity. It becomes ammunition for extortion. The group posts samples on a data leak site and demands payment to prevent full publication. No ransomware encryption. Just theft and threats. And it keeps working.

The Physical Turn in a Digital Playbook

This isn’t theoretical. The FBI’s latest advisory, released May 27, 2026, reaffirms warnings from a year earlier. Fresh incidents surfaced in spring 2026. The Register first detailed the pattern, citing the bureau’s alert that law firms remain prime targets due to the highly sensitive nature of their data (The Register).

Bleeping Computer reported the same day that SRG, also tracked as Luna Moth, Chatty Spider and UNC3753, sends a threat actor when remote social engineering falls short. “By sending someone in-person to the victim’s location to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim’s computer,” the FBI stated in its alert (Bleeping Computer).

SecurityWeek added context on the group’s history. Active since at least 2022, SRG began with fake subscription renewal emails that directed victims to call a number. Once on the line, operators pushed remote desktop tools. Success meant privilege escalation, deployment of tools like WinSCP or disguised Rclone, and exfiltration often via Google Drive or Microsoft OneDrive. The in-person option emerged as a backup plan. It still does (SecurityWeek).

Help Net Security noted the group’s broader targeting of insurance, finance and healthcare. Yet law firms have stayed a consistent focus since spring 2023. The sensitive client files — merger details, litigation strategies, personal identifiers — command high value on the extortion market (Help Net Security).

One prominent example illustrates the damage. Jones Day, a major firm with ties to former President Donald Trump, confirmed a “cyber phishing incident” in April 2026 after SRG listed it on a data leak site and claimed access to client files. The firm acknowledged some client data exposure but stopped short of naming the group, according to Reuters reporting referenced across multiple outlets.

But here’s the striking part. These aren’t sophisticated zero-days or supply-chain compromises. The attacks blend old-school social engineering with physical presence. Operatives show up at reception. They sound credible. Staff, conditioned to trust internal IT, often grant access without strong verification. A few minutes with an unlocked workstation is all it takes.

The FBI didn’t quantify exact numbers of in-person visits. It didn’t need to. The repetition in advisories signals persistence. And success.

Indicators of compromise now include unauthorized individuals claiming IT support roles, unexplained USB or external drive connections, and the presence of remote access tools installed without approval. The bureau urges organizations to treat these as red flags.

Prevention sounds basic on paper. Disable external drive connections on devices holding confidential information. Verify visitor credentials rigorously. Require phishing-resistant multifactor authentication wherever possible. Block unnecessary ports such as 22. Train staff repeatedly to challenge strangers requesting device access.

Yet the advisory’s tone reveals frustration. These recommendations have been standard for years. Implementation lags. Law firms, often structured around billable hours and client service, sometimes view security controls as friction. That mindset creates openings.

Bloomberg Law examined the broader pattern in mid-May 2026. It cataloged multiple class-action suits against law firms following breaches, including settlements reaching millions. Jones Day’s incident fit a growing list. The publication stressed embedding cybersecurity into firm governance rather than treating it as an afterthought (Bloomberg Law).

The FBI’s original advisory, available as a PDF from the Internet Crime Complaint Center, asks the public for help. Phone numbers used by the group. Call transcripts. Phishing email samples. Crypto wallet addresses. Descriptions of individuals who show up in person. Every detail aids attribution and potential disruption (IC3.gov).

SRG doesn’t deploy ransomware. It doesn’t need to. The threat of leaking stolen documents — especially those containing attorney-client privileged material — generates pressure enough. Victims face regulatory scrutiny, client loss, reputational harm and lawsuits. Payment can seem like the quieter exit.

But paying doesn’t guarantee silence. Data once taken can circulate. And the group has operated for four years. It adapts. When one vector closes, another opens. The shift to physical visits proves that point.

Recent coverage on X amplified the warnings. Security researchers and threat intelligence accounts shared the FBI alert within hours of release, highlighting the blend of digital and physical tactics. One post noted the group’s use of both remote tools and on-site USB exfiltration as a sign that modern extortion increasingly ignores keyboard-only limits.

Law firms hold troves of data that transcend typical corporate secrets. Intellectual property filings. Divorce settlements. Corporate due diligence. Health records in personal injury cases. The incentive for extortionists is obvious. So is the vulnerability when reception desks become the new perimeter.

The bureau’s message carries weight because it reflects observed behavior, not speculation. These visits happen. Staff comply. Data leaves on thumb drives. Extortion follows.

Organizations that treat physical access as an afterthought do so at their peril. The IT guy at the door might carry sophisticated tools. Or he might simply carry a USB stick. Either way, the outcome is the same if controls remain weak.

Strong identity verification for visitors. Technical blocks on unauthorized hardware. Cultural insistence that no stranger touches production devices without escort and approval. These steps don’t require advanced technology. They require discipline. Many firms still fall short.

The Silent Ransom Group counts on that gap. So far, the bet pays off.

Subscribe for Updates

EnterpriseSecurity Newsletter

News, updates and trends in enterprise-level IT security.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us