Silent Ransom Group Escalates Vishing Campaign Against U.S. Law Firms
Mandiant tracks rapid data theft following fake IT-support calls, raising fresh questions about Form 8-K Item 1.05 disclosure timing for affected firms.

A financially motivated extortion crew tracked as Silent Ransom Group is running a sustained social engineering campaign against U.S. law firms and professional services organizations, with intrusions in some cases progressing from first contact to exfiltration within hours.
The pattern matters for regulators. Law firms hold privileged client material, and any compromise touches both state breach notification regimes and, where listed clients are involved, the SEC's Form 8-K Item 1.05 cyber disclosure rule, which took effect December 18, 2023.
The group, also tracked under the names Luna Moth and Chatty Spider, has moved away from the callback-phishing emails that defined its earlier intrusions. The current playbook is voice phishing. Operators impersonate internal IT staff and call employees directly, instructing the target to install a legitimate remote management tool such as Zoho Assist, Syncro, AnyDesk, Splashtop or Atera.
Once remote access is granted, the actors enumerate file shares, stage documents, and exfiltrate using WinSCP or the Rclone command-line client. No ransomware payload is dropped. Pressure comes from the threat to publish.
Mandiant attributes the shift in tradecraft to the speed and conversion rate of live phone contact compared with email lures. Victims have included firms whose matters involve M&A, litigation holds, and regulated client data — categories that compound the disclosure analysis.
The FBI flagged the same actor in a March 2025 FLASH advisory covering U.S. legal sector targeting, noting extortion demands and threats to leak client files. That advisory predates the most recent surge in vishing-led intrusions.
For general counsel and CISOs, three regulatory pressure points are worth flagging now.
First, materiality determinations under Item 1.05 must be made "without unreasonable delay," not at the conclusion of forensic work. Second, state attorneys general — New York and California in particular — have signaled aggressive review of law firm breaches involving client PII. Third, ABA Model Rule 1.6(c) imposes an independent professional obligation to make reasonable efforts to prevent unauthorized disclosure, which plaintiffs' counsel have begun citing in civil filings.
Mandiant's recommended mitigations are operational rather than novel: application allowlisting to block unsanctioned RMM binaries, conditional access policies that restrict remote tool execution to managed endpoints, and call-back verification procedures for any inbound IT support request.
The through-line for the policy beat is timing. When initial access, exfiltration, and extortion demand can occur inside a single business day, the window for clean internal escalation — legal, executive, board — closes fast. Firms that have not rehearsed an incident response tabletop against a same-day exfiltration scenario should assume their disclosure clock will start before their forensics vendor arrives onsite.
No final rulemaking is pending that would change the analysis. The existing 8-K framework, state notification statutes, and bar ethics rules already apply.



