Silent Ransom Group (Luna Moth) chat leak: 5,692 messages claim US$206.95M in 'GOLD' payments from 27 victims in about six months, all by data theft without encryption; payments unverified
DataBreaches.net reported on 7 October 2026 that internal chats of Silent Ransom Group (SRG, also tracked as Luna Moth and UNC3753, a Conti offshoot known for IT-support callback phishing against law firms) had leaked: 5,692 messages from two servers covering 27 August 2025 to 29 September 2026, shared with the site by researcher Tammy Harper. The chats mark completed payments as 'GOLD' for 27 named targets, totalling US$206.95 million, with a median of US$6 million, a low of US$100,000 and a high of US$30 million. The group never encrypts files; it tricks staff into granting remote access, steals documents and threatens to publish them. Crystal Intelligence's blockchain analysis dates the 27 claimed payments between 3 April and 24 September 2026 and found transactions matching several chat entries, including one collection wallet that took in about 344 BTC (about US$27 million) over six weeks, but could not tie individual victims to it. Nine of the 27 named firms disclosed breaches in the same period, yet no victim has confirmed that SRG attacked it or paid the amounts listed, and SRG disputes the leak. For defenders, the lesson is that data-extortion crews without ransomware can be highly profitable; staff need to verify any 'IT support' call before installing remote tools. Primary: DataBreaches.net; wire: Cyber Security News.
- Product
- n/a (data-extortion group; callback phishing and remote-access abuse)
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- Make staff verify unsolicited IT-support calls through a known number, block unapproved remote monitoring and management (RMM) tools, and alert on large outbound document transfers, especially at law and professional-services firms.
Primary: DataBreaches.net — Can you really make more than $200M in six months without encrypting victims? (7 Oct 2026) · Cyber Security News — Leaked chat logs show Silent Ransomware extorted over $200M in 6 months (9 Oct 2026)
