According to Google and the FBI, ransomware gangs have sometimes escalated attacks on law firms by sending fake IT employees directly into victims' offices, where the imposters use USB drives to steal data directly from victims' computers or help other gang members connect to the computers remotely.
On Friday, Google's cybersecurity team Mandiant and the Google Threat Intelligence Group released a new report accusing a cybercriminal organization known as the Silent Ransom Group of attempting to steal information from “dozens” of victims “using in-person physical access” in attacks between January and May of this year.
“Mandiant has investigated a variety of issues where adversaries prime insiders, bribe employees, or physically infiltrate buildings to facilitate cyberattacks,” Mandiant Chief Technology Officer Charles Karmakar told TechCrunch in a statement, adding that the company has seen this tactic used in other cases over the years.
Last month, the FBI issued an alert warning that silent ransom groups were targeting law firms with social engineering and phishing attacks posing as IT support employees. However, in some cases, the group sent fake IT support personnel to victims' offices, where they connected to employee computers and used USB drives and remote access tools to steal data such as contracts, personal information such as Social Security numbers, and financial and tax records.
An FBI spokesperson told TechCrunch: “We can confirm multiple instances in which individuals impersonating IT support have directly physically accessed or attempted to access the offices and devices of victim companies as part of a silent ransom group's plan to exfiltrate data.”
Although current common extortion tactics do not actually encrypt the victim's data as in traditional ransomware attacks, the gang has its own leak site where it threatens victims to publish their stolen data and will do so if the victim does not pay.
Contact Us Do you have more information about these hacking campaigns? Or are they other data breaches? We would love to hear your thoughts. You can contact Lorenzo Franceschi-Bicchierai securely from any non-work device or network on Signal (+1 917 257 1382), Telegram and Keybase @lorenzofb, or email.
This often happens after the hacker sends a direct email to the victim and blackmails them.
Google said the hackers sent a letter to one of their victims saying, “In the absence of ignorance or consent, we will notify our employees, partners, and customers and then release the data.”
Google's report said hackers also used more traditional methods, including phishing emails, follow-up phone calls, and social engineering. Cybercriminals pose as corporate IT support to trick victims into allowing them access to their computers.
“The caller uses a variety of verbal commands to induce the target's behavior, building trust and enticing the target to participate in a screen-sharing session under the guise of addressing a security issue or assisting the company with a data migration project,” Google researchers wrote. Hackers then bypass security controls by convincing victims to download and open a screen-sharing application or by using screen-sharing features in apps like Zoom or Microsoft Teams.
Although hackers most often steal data remotely through malware or phishing attacks, these cases show that some hackers are taking their crimes a step further, combining traditional hacking techniques with physical intrusion to create an unprecedented escalation.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

