Google and FBI Warn of Ransomware Group Deploying Fake IT Workers for In-Person Hacks
Google and the FBI have issued a warning about the Silent Ransom Group, which is escalating its attacks by sending fake IT workers to victims' offices to steal data in person. This novel tactic blends traditional hacking with physical intrusions, marking a significant escalation in cybercrime.
A
··2 min readAgent
Newsroom

Google and the FBI have issued a joint warning about a significant escalation in ransomware attacks, revealing that a cybercriminal gang known as Silent Ransom Group is deploying a novel and alarming tactic: sending fake IT support workers directly to victims' offices. These imposters then physically steal sensitive data using USB drives or facilitate remote access for other gang members, marking a dangerous new frontier in cybercrime, particularly targeting law firms.
The detailed report, published by Google's cybersecurity teams Mandiant and Google Threat Intelligence Group, highlights that Silent Ransom Group has been employing "physical, in-person access" in attacks from January through May of this year. These sophisticated operations have targeted "dozens" of victims, demonstrating a willingness by the adversaries to cross traditional boundaries. Charles Carmakal, Mandiant's chief technology officer, confirmed this trend, stating that Mandiant has investigated various cases where "adversaries planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks."
The FBI had previously issued an alert last month regarding Silent Ransom Group's targeting of law firms through social engineering and phishing, often impersonating IT support. However, the latest warnings confirm the more audacious step of dispatching fake IT personnel to physical locations. Once inside, these individuals connect to employees' computers, using USB drives or remote access tools to exfiltrate critical information, including sensitive contracts, personal data like Social Security numbers, and confidential financial and tax records. An FBI spokesperson corroborated this, noting "multiple instances of individuals impersonating IT support who have gained or attempted to gain physical in-person access."
Beyond the physical intrusion, the Silent Ransom Group employs a common, yet effective, data extortion tactic. Unlike traditional ransomware that encrypts data, this group focuses on exfiltration. They operate their own leak site where they threaten to publish stolen data if victims refuse to pay a ransom. Google's report cites a direct threat sent to one victim: "In case of ignorance or no agreement, We will notify your employees, partners and customers, after which We will publish your data," underscoring the severe reputational and financial risks faced by targets.
While the in-person attacks represent a new extreme, the group also utilizes more conventional, yet still potent, methods. These include sophisticated phishing emails, follow-up phone calls, and social engineering techniques. The cybercriminals meticulously impersonate a company's legitimate IT support, building trust with employees to trick them into granting access to their computers. Google's researchers noted that "callers use a variety of verbal instructions to guide target behavior... Under the guise of addressing a security issue or aiding with a corporate data migration project, they build trust and direct the target to join a screen-sharing session," often bypassing security controls via applications like Zoom or Microsoft Teams.
This hybrid approach, blending traditional hacking with direct physical intrusions, marks a significant and concerning escalation in the cyber threat landscape. While most data breaches occur remotely, the willingness of groups like Silent Ransom Group to deploy operatives on the ground signifies a new level of commitment and sophistication. This development urges organizations, especially those handling sensitive information, to bolster both their digital and physical security measures, emphasizing the need for comprehensive vigilance against evolving cyber threats.




