FBI warns of new in‑person ransomware attacks targeting law firms
The U.S. Federal Bureau of Investigation has issued an alert about a novel hacking technique in which attackers impersonate IT support staff, call a company’s help desk, and then physically enter the office to install a device that steals data for extortion. The campaign, currently focused on law firms, also affects the pharmaceutical and insurance sectors. The group behind the operations is identified as Silent Ransom Group, active since at least 2023 and reportedly began on‑site attacks in 2025.
The method relies on minimal privilege escalations, using legitimate system‑admin tools such as Zoho Assist, AnyDesk, WinSCP or Rclone, leaving few forensic traces. Victims often receive ransom letters or calls after their data is exfiltrated. The FBI recommends verifying the identity and authorization of anyone entering a company’s premises, training staff to recognize phishing and social‑engineering attempts, maintaining regular backups, and enforcing two‑factor authentication for all users.