Silent Ransom Group allegedly extorted $207 million from 27 law firms in six months using phone calls and social engineering, not encryption.Silent Ransom Group doesn’t rely on encryption. No malware payload, no locked files, just phone calls and social engineering aimed almost entirely at law firms, and apparently it works extraordinarily well. A new leak of the group’s internal chats, first shared with DataBreaches by researcher Tammy Harper, backs that up with numbers. The leaked data comes from two of the group’s servers and covers about 13 months, from August 2025 to September 2026. It contains 5,692 chat messages about ransom negotiations, ways to access victims’ systems, and plans for future targets. “The leak was first shared with this site by Tammy Harper as an onion site with 5,692 chat messages that discuss victim payments, possible access methods, approaches to future victims, the purchase of an apartment in Moscow by one of the members, and discussions of guns and drones, among other topics.” reads the report published by DataBreaches.The chats also discuss personal matters, including one member buying an apartment in Moscow, as well as guns and drones. The conversations sound less like a secret criminal operation and more like a sales team sharing tips on how to make money.The group’s internal records claim that 27 law firms paid around $207 million in ransom payments between April and September 2026. Crystal Intelligence examined the cryptocurrency transactions and money laundering activity, concluding that blockchain data supports the overall scale of the operation but does not confirm the exact amounts.“The group’s internal deal board claims about $207M paid by 27 firms between April 3 and September 24, 2026. On-chain evidence supports the scale but not the exact figures.” “continues the report. Payouts followed strict wallet rules designed to defeat tracing. The operators didn’t always follow them.”The median payment across those 27 firms was $6 million, with the arithmetic mean pulled up to about $7.66 million by a handful of enormous outliers.The single largest payment, $30 million from White & Case, prompted one of the group’s leaders to celebrate in Russian, writing roughly “record gold, brother, due to the growth of the BTC exchange rate it ended up at 31.25 million.” Bitcoin’s price swings apparently cut both ways, even for the criminals collecting it. There’s something almost absurd about a ransomware crew sweating crypto volatility like a day trader.Crystal Intelligence’s breakdown of the group’s cash-out process is where this stops being a story about hackers and starts being a story about money laundering mechanics. Payments ran through instant exchangers, a cash courier in Moscow, a Bitcoin-to-Zelle desk, and a coin-mixing wallet whenever funds got flagged as suspicious. The operators had strict wallet rules designed to defeat tracing, but the chats show they didn’t always follow their own rules.“Many smaller payments went straight to regulated exchanges, where accounts are tied to verified identities.” states the report. “This is the network’s weakest point.”Sloppy operational security from criminals pulling in hundreds of millions of dollars is either reassuring or deeply unsettling, depending on how charitable you’re feeling.DataBreaches cross-referenced nine of the 27 named victims against public breach disclosures filed in 2026, and the timing lines up. Blank Rome disclosed a May incident where an attacker posed as internal IT and convinced an attorney to upload files to an external Google Drive, a classic Silent Ransom Group move with no malware required at all. Goodwin Procter confirmed something similar, stating plainly that a single employee was deceived into handing over credentials to an unauthorized party.Not every claim holds up cleanly, though. DataBreaches found a chat entry showing Hogan Lovells Cadwalader offered $4 million on September 2, which matched screenshots the group had separately provided, but there’s no record the firm ever paid the full “GOLD” amount SRG claims on its leak site. Sheppard, another named firm, shows up in SRG’s leak site notes claiming an offer near $6 million, yet the chat logs show no indication the firm ever responded to the group at all. Someone’s math doesn’t add up, and it’s worth remembering a criminal’s accounting isn’t exactly audited.The most important point is not the amount of money involved, impressive as it may be. Silent Ransom Group shows that criminals can make huge profits without using malware or encrypting files. They can rely on phone calls and tricking employees into uploading documents or sharing access. Law firms are attractive targets because they hold sensitive client information that criminals can use to demand large payments. This case also shows that security training may not be keeping up with these tactics.Silent Ransom Group initially agreed to an interview but denied that its systems had been breached. On October 9, DataBreaches published a follow-up with additional evidence challenging the group’s denial. The situation remains unresolved.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, Silent Ransom)