// AI threat desk · 9 Oct 2026
Home/AI-ATK · AI-Powered Attacks
AI-Powered AttacksMediumSRGCVSS not assigned

Silent Ransom Group chats showed plans for physical intrusions and extortion

Recorded Future News said leaked chats described plans to enter U.S. law firms, kidnap business executives and recruit military personnel. The archive contained thousands of messages.

AI-generated image of security analysts reviewing blurred chat archives and physical intrusion alerts in a dim operations centre.
AI-generated image, not a photo of the event.
Key takeaways
  • Recorded Future News said the archive described plans to send operatives into U.S. law firms, kidnap business executives and recruit military personnel.
  • Recorded Future News said the archive contained thousands of messages from August 2025 to September 2026.
  • Chainalysis said cryptocurrency addresses in the leak could be tied to known Silent Ransom Group extortions.

Recorded Future News said leaked chats showed Silent Ransom Group members planning to send operatives into U.S. law firms, kidnap business executives and recruit military personnel to spy on submarine-based nuclear forces.

The archive contained thousands of messages from August 2025 to September 2026. Recorded Future News said about 50 organizations, mostly law firms, appeared in the records.

Crystal Intelligence said Silent Ransom Group, also tracked as Luna Moth, is a data-extortion group that emerged after Conti shut down in 2022, and that it tricks staff into granting remote access, steals data and threatens to publish it without encrypting files.

On this page

The archive mixed extortion records with proposed operations

Recorded Future News said the archive mixed apparent extortion records with brainstorming, abandoned plans, boasting and violent fantasies. It said the archive’s most extreme schemes could not be verified as attempted.

The FBI had warned earlier in 2026 that Silent Ransom Group members were posing as IT personnel to gain physical access to computers.

Recruitment used job listings and paid Telegram advertisements

Recorded Future News said the group recruited agents through paid Telegram advertisements disguised as ordinary job listings, including nightclub promotion, courier work and security. It said the group’s apparent leader estimated in February that only one in 10 recruits proved usable.

Crystal Intelligence said Russian-language job boards offered field agents more than $300 per night for nightclub-promoter work, but respondents were instead pushed into physical intrusion work.

Blockchain records linked wallets to extortion payments

Chainalysis said certain leaked Silent Ransom Group addresses were downstream of millions of dollars in ransomware payments that the group extorted from victims. It also said two group wallet addresses received hundreds of thousands of dollars from a known member’s wallet.

Chainalysis said one wallet named in the chats was funded entirely from a victim payment exceeding $10 million that Silent Ransom Group collected in mid-2026.

Recorded Future News said the archive listed roughly $200 million in claimed settlements across dozens of firms marked gold, but those figures could not be independently verified. Crystal Intelligence separately said the chats claimed about $207 million from 27 firms between April and September 2026, a total it could not verify.

Crystal Intelligence traced funds to an upstream wallet

Crystal Intelligence said it traced funds to an upstream collection wallet that received about 2,675 Bitcoin over its lifetime. Crystal Intelligence published its analysis on Oct 6, 2026.

The Register reported that the leaked website claimed nearly 5,700 internal messages identifying senior members and field agents.

Recorded Future News said it could not verify whether the archive’s most extreme schemes were attempted. The archive was posted to a bespoke .onion site in early October by an unidentified source that did not state a motive.

Chainalysis said it could tie cryptocurrency addresses in the leak to known Silent Ransom Group extortions, while cautioning that it could not “speak to the totality of claims” in the archive.

FAQ

What did the Silent Ransom Group chats reveal?

Recorded Future News said the chats described plans to send operatives into U.S. law firms, kidnap business executives and recruit military personnel. It also said the archive mixed apparent extortion records with brainstorming, abandoned plans, boasting and violent fantasies.

Who posted the Silent Ransom Group archive?

Recorded Future News said the archive was posted to a bespoke .onion site by an unidentified source that did not state a motive. Crystal Intelligence said Silent Ransom Group is also tracked as Luna Moth and emerged after Conti shut down in 2022.

Was Silent Ransom Group’s physical intrusion plan carried out?

Recorded Future News could not verify whether the archive’s most extreme schemes were attempted. The FBI separately warned that people posing as IT support staff were entering law offices and copying files onto USB drives.

How did Silent Ransom Group recruit operatives?

Recorded Future News said the group used paid Telegram advertisements disguised as ordinary job listings, including nightclub promotion, courier work and security. Crystal Intelligence said Russian-language job boards offered more than $300 per night for nightclub-promoter work before respondents were pushed toward physical intrusions.

How much money did the leaked chats claim Silent Ransom Group received?

Crystal Intelligence said the chats claimed about $207 million from 27 firms between April and September 2026, but it could not verify that total. Recorded Future News said the archive listed roughly $200 million in claimed settlements, which also could not be independently verified.

Sources

  1. Inside the Silent Ransom Group leak: how ransoms were laundered, Crystal IntelligencePrimary
  2. Leaked chats show Russian extortion gang sending ‘agents’ into US law firms, The Record
  3. Money trail backs leaked chats from extortion crew that walks into US law firms, The Register
How we checked this story
ClaimSourceStatus
Recorded Future News reported that Russia-based cyberextortion gang members plotted to send operatives into U.S. law firms, kidnap executives and recruit military personnel.Recorded Future News, via The RecordAttributed
Recorded Future News said the archive was posted to a bespoke .onion site in early October by an unidentified source that did not state a motive.Recorded Future News, via The RecordAttributed
Recorded Future News said the archive contained thousands of messages from August 2025 to September 2026.Recorded Future News, via The RecordAttributed
Recorded Future News said the archive mixed apparent extortion records with brainstorming, abandoned plans, boasting and violent fantasies.Recorded Future News, via The RecordAttributed
Recorded Future News could not verify whether the archive’s most extreme schemes were attempted.Recorded Future News, via The RecordAttributed
Chainalysis said cryptocurrency addresses in the leak could be tied to known extortions by Silent Ransom Group.Chainalysis, via The RecordAttributed
Chainalysis cautioned that it could not speak to the totality of claims documented in the archive.Chainalysis, via The RecordAttributed
The FBI warned earlier in 2026 that Silent Ransom Group members were posing as IT personnel to gain physical access to computers.FBI, via The RecordAttributed
Recorded Future News said the archive listed roughly $200 million in claimed settlements across dozens of firms marked gold, but those figures were not independently verified.Recorded Future News, via The RecordAttributed
Recorded Future News said about 50 organizations, mostly law firms, appeared in the records.Recorded Future News, via The RecordAttributed
Recorded Future News said the group recruited agents through paid Telegram advertisements disguised as ordinary job listings, including nightclub promotion, courier work and security.Recorded Future News, via The RecordAttributed
Recorded Future News said the group’s apparent leader estimated that only one in 10 recruits proved usable.Recorded Future News, via The RecordAttributed
The Register reported that Chainalysis found certain leaked Silent Ransom Group addresses downstream of millions of dollars in extorted ransomware payments.Chainalysis, via The RegisterAttributed
Chainalysis said two Silent Ransom Group wallet addresses received hundreds of thousands of dollars from a known member’s wallet.Chainalysis, via The RegisterAttributed
Chainalysis said one wallet named in the chats was funded entirely from a victim payment exceeding $10 million collected in mid-2026.Chainalysis, via The RegisterAttributed
Crystal Intelligence said the chats claimed Silent Ransom Group received about $207 million from 27 firms between April and September 2026, but it could not verify that total.Crystal Intelligence, via The RegisterAttributed
Crystal Intelligence traced funds to an upstream collection wallet that received about 2,675 Bitcoin over its lifetime.Crystal Intelligence, via The RegisterAttributed
The Register reported that the leaked website claimed nearly 5,700 internal messages identifying senior members and field agents.The RegisterAttributed
Crystal Intelligence said field agents were recruited through Russian-language job boards offering more than $300 per night for nightclub-promoter work.Crystal Intelligence, via The RegisterAttributed
The FBI warned in May that people posing as IT support staff were entering law offices and copying files onto USB drives.FBI, via The RegisterAttributed
Silent Ransom Group is a data-extortion group also tracked as Luna Moth that emerged after Conti shut down in 2022.Crystal IntelligenceConfirmed
Silent Ransom Group tricks staff into granting remote access, steals data and threatens to publish it without encrypting files.Crystal IntelligenceConfirmed
crystalintelligence.com published its report on Oct 6, 2026.crystalintelligence.comConfirmed

Could not verify

  • Whether the archive’s most extreme schemes were attempted is not established.
  • Whether U.S. service members were recruited or military or nuclear information was obtained is not established.
  • Whether the claimed settlement totals represent actual payments is not established.
  • Whether Silent Ransom Group has a confirmed relationship with the Russian state is not established.
Explore with AI