A trove of data posted online this week has exposed cryptocurrency wallets used by the Silent Ransom Group (SRG), a hacking outfit known for extorting large sums from law firms across the United States. The leak, shared by an anonymous source under the banner “The Luna Moth Files,” includes chat logs, ransom demand totals, and dozens of wallet addresses tied to the group’s operations.
What the leak reveals
Blockchain analytics firm Chainalysis examined the leaked information and confirmed that several of the disclosed wallet addresses have been linked to multi‑million‑dollar ransomware payments. One address, already tracked by Chainalysis before the leak, reflects a $10 million payment collected by SRG in mid‑2026. The firm noted that “certain leaked SRG addresses sit downstream of millions of dollars in ransomware payments that SRG has extorted from victims.”
The FBI has warned that SRG targets specific employees at law firms, using phone calls, emails, and sometimes in‑person visits to gain access to victims’ computers. Once inside, the group can move laterally across the firm’s network, steal sensitive data, and then demand payment to prevent public disclosure.
Law firms under attack
SRG has been implicated in attacks on prominent firms such as Fox Rothschild and Jones Day, according to prior Reuters reporting. The group’s strategy focuses on high‑value legal practices that store confidential client information, making the threat especially concerning for the legal profession and its clients.
Law firms typically respond to such breaches by engaging forensic investigators, notifying affected clients, and, in many cases, paying the demanded ransom to halt the release of stolen data. The financial impact of these extortion schemes runs into the tens of millions of dollars, as illustrated by the $10 million payment identified in the leak.
Law enforcement and industry response
Federal authorities, including the FBI, continue to investigate SRG’s activities and have urged firms to strengthen cybersecurity defenses. Recommendations include implementing multi‑factor authentication, conducting regular security audits, and training staff to recognize phishing attempts.
Chainalysis, which tracks illicit cryptocurrency activity, says the leak provides valuable insight into how ransomware groups move stolen funds through the blockchain. By mapping these transactions, investigators can better trace the flow of money and potentially disrupt the financial infrastructure that supports cyber‑crime operations.
What this means for businesses
While the leak focuses on law firms, the tactics employed by SRG are applicable to any organization that holds valuable data. Companies of all sizes should review their security posture, ensure backups are isolated from live networks, and consider cyber‑insurance policies that address ransomware risk.
Cybersecurity experts stress that proactive measures are far more cost‑effective than paying ransoms after a breach. As ransomware groups become more sophisticated, the need for robust defenses and rapid incident‑response plans grows increasingly urgent.
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.