Silent Ransomware Group Amassed $200M by Stealing Data, Not Encrypting It
Leaked chat logs allegedly reveal the Silent Ransom Group, also known as Luna Moth, extorted over $200 million from 27 organizations in six months by threatening to release stolen data rather than encrypting it.

Internal communications purportedly from the Silent Ransom Group, also tracked as Luna Moth and UNC3753, suggest the cybercriminal organization amassed approximately $206.95 million from 27 victim organizations over a six-month period. This substantial sum was reportedly generated not through traditional file encryption, but by stealing sensitive data and threatening its public release, a tactic known as data extortion. The alleged leak, first reported by DataBreaches, comprises over 5,600 messages spanning from August 2025 to September 2026, detailing victim negotiations, payment structures, and operational methods.
While the reported earnings are unverified and the group has disputed the leak's origin, the figures offer a stark illustration of the lucrative nature of data exfiltration. Crystal Intelligence, a threat intelligence firm, analyzed the purported chats and blockchain transactions. Their findings indicate that the 27 "GOLD" deals, marked as completed within the logs, occurred between April and September 2026. The median alleged payment was $6 million, with individual ransoms ranging from $100,000 to a reported $30 million for White & Case.
Blockchain analysis by Crystal Intelligence identified significant money movement consistent with the reported timeline, including a collection wallet that received around 344 bitcoin, valued at approximately $27 million, over a six-week span. However, researchers could not definitively link individual victim payments to this specific wallet, meaning the total sum remains unconfirmed. The analysis did reveal that some operators occasionally combined payouts, creating traceable transaction chains, while others attempted to use fresh wallets for each victim to obscure their activities.
Silent Ransom Group, which emerged after the Conti ransomware group's dissolution in 2022, has focused heavily on law firms. This strategic targeting is likely due to the highly sensitive and confidential client information these firms possess. The group's modus operandi involves impersonating internal IT support staff to trick employees into granting remote access to their systems. This social engineering tactic allows them to bypass traditional security measures that might flag more overt malware infections.
Once access is established, the attackers utilize tools like WinSCP and Rclone to exfiltrate large volumes of data. The pressure on victims stems from the potential exposure of privileged client communications, trade secrets, and personal identifiable information, rather than the immediate disruption of services caused by file encryption. This approach can be particularly effective against organizations where data confidentiality is paramount.
Defensive strategies against this type of attack emphasize robust identity verification and employee training. Verifying support requests through established internal channels before granting remote access is crucial. Furthermore, organizations should implement strong access controls, deploy phishing-resistant multi-factor authentication, and continuously educate staff on recognizing and reporting social engineering attempts, particularly those conducted via phone.
The group's methods for cashing out funds include using instant cryptocurrency exchangers, employing couriers, and utilizing services that convert Bitcoin to platforms like Zelle, making the financial trail more complex to follow. However, the use of regulated exchanges and the occasional commingling of funds by operators provide potential avenues for law enforcement and researchers to track illicit financial flows.
This case highlights a significant trend in the ransomware landscape, where the threat of data exposure has become as potent, if not more so, than file encryption. The success of groups like Silent Ransomware underscores the need for organizations to prioritize data security and implement comprehensive measures to prevent unauthorized access and exfiltration.