< Back to all clusters
[TECHNOLOGY] · United States · 4 sources

Silent Ransom Group escalates ransomware attacks with physical IT imposters

A cyber‑crime gang identified as Silent Ransom Group, also tracked as UNC3753, has expanded its extortion tactics against dozens of U.S. banks, law firms and other professional services. Between January and May, the group used typical social‑engineering methods—phishing emails, fake help‑desk calls and screen‑sharing requests—to gain remote access, but in several incidents it sent imposters posing as on‑site IT support staff. The intruders entered victim offices, connected USB thumb drives to computers and stole sensitive data such as contracts, personal identifiers and financial records, which they later threatened to publish on a leak site unless a ransom was paid.

Google’s Mandiant team and the FBI confirmed the physical intrusion tactic, noting that the attackers can move from remote data theft to on‑site theft within a single day. The gang’s rapid operations often progress from initial contact to data exfiltration in under an hour. Victims reported that the imposters claimed they needed to image devices or create backups, exploiting trust to bypass security controls. The campaign highlights a novel escalation where traditional ransomware methods are combined with direct, in‑person data theft.

The FBI and Google have issued alerts warning organizations to verify the identity of any on‑site IT personnel and to be wary of unsolicited help‑desk calls, especially those that request screen‑sharing or USB device usage.