The FBI warns that a cybercriminal group is sending fake IT workers into offices to steal data. Learn how to protect your organization from in-person tech support impersonator scams.
Your employees know to avoid clicking suspicious links. They've been through phishing training. But what happens when the threat walks through the front door — and your receptionist holds it open?
That's no longer a hypothetical. The FBI issued a warning in May 2026 about a cybercriminal group called the Silent Ransom Group (SRG) that is physically sending impersonators into businesses, posing as IT support staff, to plug storage devices directly into employee computers and steal sensitive data. If your security strategy stops at the firewall, this threat has already passed you.
Who Is the Silent Ransom Group — and Why Should You Care?
The Silent Ransom Group (also tracked by researchers as Luna Moth, Chatty Spider, and UNC3753) has been running data theft and extortion operations since at least 2022. Unlike typical ransomware gangs, SRG skips the encryption step entirely. Their goal is speed: get in, grab data, get out — then extort the victim with threats of public disclosure or sale of the stolen information.
Law firms have been a primary target, given the treasure trove of privileged communications, financial records, client data, and case strategy documents they hold. But the tactics SRG uses are transferable to any industry, including financial services, healthcare, and manufacturing — sectors where InfoSight works every day.
The Old Playbook: Callback Phishing
Historically, SRG relied on a clever twist on phishing. Victims received emails warning them of a fake subscription charge. To cancel, they were told to call a phone number — which connected them directly to an SRG actor posing as a support agent. From there, the attacker convinced the employee to download remote access software, handing over the keys to the network.
It worked. And it's still in use today.
The New Tactic: Showing Up in Person
What's new — and alarming — is what SRG added in early 2026: physical impersonation.
When the remote access approach fails, SRG dispatches someone to the victim's physical location. This person poses as an IT support technician and presents a plausible excuse — they need to "image the device" or create a backup to address a potential phishing issue. Once they have access to a workstation, they insert a storage device and exfiltrate data directly. In some cases, they also install remote access tools to establish a persistent foothold for later.
The FBI notes that once the data is secured, SRG doesn't stop at the company. They will call employees and clients of the victim organization directly to apply pressure and force payment negotiations.
This is not a theoretical attack vector. The FBI issued a formal Flash report and is actively collecting evidence — including surveillance footage of individuals posing as IT staff.
Warning Signs: What the FBI Says to Watch For
Security and IT teams should treat the following as red flags that a Silent Ransom Group-style attack may be underway:
Unidentified individuals appearing on-site claiming to be IT support
Unsolicited phone calls from someone claiming to work in your IT department
Unauthorized downloads of remote access tools such as Zoho Assist, AnyDesk, RustDesk, Quick Assist, Syncro, Splashtop, or Atera
Unauthorized connection of external hard drives or USB devices to company computers
Data transfers to Microsoft OneDrive, Google Drive, or unknown external servers
WinSCP or Rclone connections to external IP addresses
Alerts indicating data was exfiltrated from the company environment
If any of these indicators appear in your environment, treat it as a potential active incident — not a false positive to be investigated at leisure.
Why Employees Fall For It
Security experts point to a consistent psychological pattern: employees default to trust, especially when someone presents themselves with authority and urgency. A person who walks in wearing a polo shirt, references a specific IT issue, and projects confidence is going to get access — unless employees have been specifically trained to challenge that scenario.
The problem is compounded in organizations that outsource IT support to a third party. Employees often have no idea who their "real" IT contact looks like or how they would identify themselves, making it nearly impossible to spot an impersonator without a defined verification process in place.
There's also a hierarchy problem. Security awareness training too often skips the people at the top (who assume they're not targets) and the people at the front desk (who are, in fact, the first line of defense).
What Strong Defenses Look Like
Protecting against in-person social engineering requires a layered approach that combines policy, technology, and training:
1. Establish a verified IT contact protocol.
Every employee — from the C-suite to the reception desk — should know the exact process for verifying an IT support request. That process should never involve calling a phone number provided in the suspicious message or email.
2. Train employees to slow down.
Urgency is a manipulation tactic. Employees should be empowered to pause, verify, and escalate without fear of seeming unhelpful or paranoid.
3. Disable USB ports where appropriate.
Windows has had native controls to restrict unauthorized storage device connections for over a decade. Many organizations simply haven't enabled them. This is a low-cost, high-impact control.
4. Apply physical security to your security program.
Visitor credentialing, photo ID verification, and escorted access to workspaces aren't just for government buildings. For organizations handling sensitive data, these are baseline expectations.
5. Conduct penetration testing that includes physical scenarios.
Physical attack simulations — including attempts to tailgate into the building or impersonate a vendor — are a core part of a mature security testing program. If your last pen test only covered your network, you have a gap.
6. Extend security awareness to every level of the organization.
Social engineering exploits the human layer. The receptionist who buzzes in the "IT guy" matters just as much as the employee who downloads the remote access tool.
The Bottom Line for Mid-to-Large Enterprises
The Silent Ransom Group is a reminder that sophisticated threat actors don't limit themselves to one attack surface. They probe for the weakest point — and increasingly, that point is not your technology. It's your people and your physical environment.
For organizations in financial services, healthcare, and manufacturing, where regulatory obligations and data sensitivity are high, an incident of this nature carries consequences well beyond the immediate breach: client notification obligations, reputational damage, regulatory scrutiny, and in the case of law firms, exposure of privileged communications that cannot be undone.
The question isn't whether your organization could be targeted. The question is whether your employees, your policies, and your security program are prepared for a threat that doesn't come through email — it comes through the door.
Is your organization ready for the full spectrum of social engineering threats?
InfoSight offers comprehensive security assessments, employee security awareness training programs, and penetration testing that includes physical security scenarios. Contact our team to learn how we help mid-to-large enterprises close the gaps that attackers are already exploiting.
Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.
One follow-up from a security expert—no spam, ever.
Enter your details below to download the PDF.