{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:09.355Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"FBI warns Silent Ransom Group is callback-phishing US law firms","date":"2025-05","date_precision":"month","victim_org":"US law firms and legal services organisations (campaign)","sector":"Legal","country":"United States","primary_vector":"Callback Phishing (TOAD)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the FBI advisory.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the group extorts victims after data theft without deploying encryption.","records_affected":null,"threat_actor":"Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, UNC3753)","summary":"The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.","how_it_worked":"The primary lure is a telephone-oriented attack delivery email: a message claims a small subscription has been renewed and will be charged unless the recipient calls a number to cancel. There is no link or attachment, so the mail passes gateway filtering. When the victim calls, the operator, posing as support, directs them to a website and has them install a legitimate remote access utility such as Zoho Assist, Syncro, AnyDesk, SuperOps or Atera. The group has also skipped the email entirely and simply telephoned employees claiming to be the firm's own IT department with an after-hours maintenance request. Once connected, the operators escalate where possible, use tools such as WinSCP or Rclone to exfiltrate documents, then extort the firm by threatening publication on a leak site.","lessons":"Application control that blocks unapproved remote access tools is the decisive check here, since the email carries no malicious payload for a gateway to catch; staff also need a verified internal number for IT so an unexpected support call can be refused.","confidence":"Confirmed","sources":[{"title":"FBI warns of Luna Moth extortion attacks targeting law firms","url":"https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/","publisher":"BleepingComputer"},{"title":"Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign","url":"https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html","publisher":"The Hacker News"},{"title":"FBI warns of cybercriminals impersonating IT staff to breach law firms","url":"https://www.floridabar.org/the-florida-bar-news/fbi-warns-of-cybercriminals-impersonating-it-staff-to-breach-law-firms/","publisher":"The Florida Bar"}],"entry_type":"campaign","slug":"2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms"}]}