Leak exposes payments made to hacking group that has extorted millions from law firms
Key Points
- An unknown party published 'The Luna Moth Files' containing alleged SRG data including chat logs, ransom demand totals, and dozens of cryptocurrency wallet addresses
- Chainalysis verified that certain leaked addresses were already being tracked and contain millions in extorted ransomware payments, including a $10 million payment from mid-2026
- The FBI reported SRG targets specific law firm employees with phone calls to facilitate data theft, with prominent law firms allegedly among the victims
AI Summary
Summary: Leak Exposes Payments to Silent Ransom Group Targeting Law Firms
A data leak has revealed payment information related to Silent Ransom Group (SRG), a cybercriminal organization that has extorted millions from law firms through targeted hacking campaigns. The leak was analyzed by blockchain investigations firm Chainalysis on October 7.
Key Details:
An anonymous source published extensive data allegedly belonging to SRG on a website called "The Luna Moth Files" earlier this week. The leaked information includes chat logs, ransom demand totals, internal documents, and dozens of cryptocurrency wallet addresses used by the group.
Financial Impact:
Chainalysis confirmed that certain leaked cryptocurrency addresses are "downstream of millions of dollars in ransomware payments" extorted by SRG. One tracked wallet address showed a single victim payment of $10 million collected in mid-2026. The FBI issued warnings in May about SRG's operations, noting the group demands millions of dollars to prevent stolen data from being published.
Methodology:
The FBI reports that SRG employs sophisticated social engineering tactics, specifically targeting law firm employees through phone calls to gain access to sensitive systems and data.
Affected Entities:
While specific law firm names were redacted in the article, Reuters previously reported that prominent law firms have fallen victim to SRG attacks.
Verification Status:
Reuters could not immediately authenticate the leaked data's legitimacy, though Chainalysis validated certain cryptocurrency addresses were already under their surveillance prior to the leak.
Market Implications:
This breach highlights ongoing cybersecurity vulnerabilities in the legal sector and underscores the financial risks facing professional services firms from ransomware operations utilizing cryptocurrency for anonymous payments.
Model Analysis Breakdown
| Model | Sentiment | Confidence |
|---|---|---|
| GPT-5-mini | Neutral | 80% |
| Claude 4.5 Haiku | Bearish | 70% |
| Gemini 2.5 Flash | Neutral | 85% |
| Consensus | Neutral | 78% |