Fake IT staff raid offices to steal data, Google warns – Claril Noticias

Google and the FBI have warned that a ransomware gang targeted dozens of US law firms between January and May by sending fake IT workers directly into offices to physically steal sensitive data. These imposters gained access to corporate computers to extract files using USB drives or to help external accomplices connect to the systems remotely.

In-Person Infiltration: A Dangerous New Tactic

Google’s cybersecurity divisions, Mandiant and the Google Threat Intelligence Group, recently published a new report exposing the cybercriminal syndicate known as the Silent Ransom Group (SRG). The group carried out these audacious physical breaches over a five-month period, compromising numerous high-value targets.

Mandiant’s chief technology officer, Charles Carmakar, noted that whilst physical intrusions, bribing employees, or planting insiders are uncommon, they are established tactics that the firm has observed across various cyber-campaigns over the years.

Corroborating these findings, the FBI published an alert detailing how the group combined social engineering with physical visits. Imposters posing as IT support technicians successfully gained physical access to corporate offices, using USB drives and remote access software to exfiltrate critical data, including legal contracts, Social Security numbers, and financial records.

An FBI spokesperson confirmed that the agency has documented multiple instances where individuals impersonating IT support staff successfully breached or attempted to breach physical corporate offices to steal data as part of this specific campaign.

How the Silent Ransom Group Operates

Rather than deploying traditional ransomware that encrypts a victim’s local systems, the Silent Ransom Group relies entirely on data exfiltration and extortion. The group hosts a dedicated leak site where they threaten to publish stolen corporate data unless a ransom is paid.

The gang typically initiates contact via direct, threatening emails to pressure victims. According to Google, one such communication warned a victim: “In case of ignorance or no agreement, We will notify your employees, partners and customers, after which We will publish your data.”

A Hybrid of Physical and Digital Deception

Despite the physical aspect of their operations, the hackers still rely heavily on digital manipulation. They employ phishing emails, follow-up telephone calls, and social engineering to build trust before any in-person attempt.

By pretending to assist with urgent security patches or corporate data migrations, the callers guide victims into screen-sharing sessions via platforms like Zoom or Microsoft Teams. Once connected, they convince the targets to bypass security controls and download remote-access applications.

While most cybercriminals operate exclusively from behind a screen, this hybrid approach represents a significant escalation, merging digital manipulation with real-world deception.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *