Payment rates have fallen to a record low, and the large payouts that remain can largely be traced to one malicious group focused on the legal sector.

 

What happened

The share of extortion victims choosing to pay has dropped to its lowest recorded level, with the few remaining large payouts tracing mostly to high-profile law firms hit by a single group, BankInfoSecurity reported on August 3, 2026. That group is the Silent Ransom Group, also tracked as Luna Moth, Chatty Spider, UNC3753, and Storm-0252. It does not deploy ransomware in the conventional sense, since it neither encrypts files nor locks systems. The entire model rests on stealing data and threatening to publish it, which works on organizations whose business depends on confidentiality. Declining payment rates across the wider criminal population and rising extremity of tactics among specific groups are two halves of the same picture.

 

Going deeper

The FBI published FLASH-20260526-01 on May 26, 2026, warning US law firms that the group impersonates IT support through phone calls and phishing emails, then steals sensitive material and demands payment to keep it private, as CyberScoop reported. The bureau had issued an earlier advisory a year prior, which indicates a threat that persisted rather than one that passed. The group's methods have moved through distinct phases since 2022, beginning with callback phishing using fake subscription invoices, shifting to direct voice phishing that impersonated internal IT staff from March 2025, and most recently adding physical intrusion. What has stayed constant is the absence of malware, since the group works through social engineering and legitimate administrative software rather than custom tooling. Its targeting reflects a specific commercial judgment, concentrating on organizations that hold confidential client material and have strong reasons to settle quietly.

 

What was said

The group "leverages voice phishing (vishing) and social engineering deception techniques" to reach corporate environments remotely, Google wrote in research reported by Dark Reading in June 2026. Google described operators using pretexts such as data migration projects or invoice queries to open a phone conversation while posing as IT support, then persuading the target to host a screen-sharing session and download remote monitoring and management software. Between January and May 2026, the group approached dozens of organizations this way.

 

In the know

The escalation the FBI documented has no recent precedent among extortion crews. Operators posing as IT personnel walked into target offices in person, convinced staff they were there for routine maintenance, and connected storage devices directly to workstations to copy files, according to Dark Reading's account of the research. Physical presence defeats the entire perimeter, since no email filter, firewall rule, or network monitoring control sits between a person standing at a desk and the machine in front of them. The tactic appears to serve as a fallback, deployed when remote impersonation fails rather than as a first approach. Organizations that have rehearsed responses to suspicious calls have generally not rehearsed what a receptionist should do when someone arrives claiming to be from IT.

 

The big picture

Extortion without encryption changes what a healthcare organization is defending against and how it detects the problem. Nothing goes down, no ransom note appears on a screen, and clinical operations continue normally while data leaves the building, which means the first sign is often a phone call from the attacker. The regulatory position does not soften as a result, since HIPAA breach determination turns on whether protected health information was accessed or acquired without authorization rather than on whether anything was encrypted, as HHS sets out in the Breach Notification Rule. Detection has to come from data movement rather than system disruption, which means monitoring for unusual outbound transfers, unexpected use of file transfer utilities, and remote access sessions that no ticket accounts for. The falling payment rate suggests organizations are getting better at refusing, and the groups still succeeding are the ones that picked targets who cannot afford disclosure.

 

FAQs

Why would an extortion group abandon encryption entirely?

Encryption is the noisiest part of an attack and the part most likely to trigger detection, incident response, and law enforcement involvement. Removing it lowers operational risk while preserving the leverage, provided the stolen data is sensitive enough that publication alone is unacceptable to the victim.

 

What legitimate tools do these groups rely on?

File transfer utilities and remote access software that already exist in most environments or install without administrative rights. Because the software is genuine, detection depends on identifying unauthorized use rather than malicious code, which requires knowing what is normally installed and who normally uses it.

 

How should a front desk handle an unscheduled IT visit?

Treat it as a verification problem rather than a courtesy question. No one gains physical access to workstations without a ticket number confirmed through internal channels and an escort, and staff should be told explicitly that turning away a genuine technician is an acceptable outcome.

 

Does refusing to pay affect breach notification obligations?

No. Notification duties attach to the unauthorized access itself, and the decision to pay or not has no bearing on them. Organizations that pay still notify, and organizations that refuse are in the same position regarding regulators and affected individuals.

 

What explains the drop in payment rates?

Better incident response and recovery capability, greater regulatory scrutiny of payments, law enforcement disruption of groups and laundering routes, and accumulated evidence that paying does not reliably result in data being deleted. Each factor makes refusal a more defensible decision for a board.