Social Engineering Gets Personal: What the FBI's Silent Ransom Group Warning Means for Law Firms
Steve McMaster Chief Information Security Officer Western Alliance BankAttackers are counting on employees to trust what appears to be a legitimate request and respond before taking the time to verify it.
Cybercriminals continue to change their tactics, and the FBI's latest warning points to a growing risk for law firms and other organizations that handle sensitive client information: attacks that target trust, not just technology.
The FBI recently issued an intelligence bulletin regarding the Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider and UNC3753. The group has targeted U.S.-based law firms, with activity also seen in other sectors, by impersonating internal IT personnel through phone calls, phishing emails and, in some cases, in-person visits.
For law firms, the stakes are especially high. Attackers may seek access to client files, confidential business records, financial information and other sensitive materials. The same risks can extend to accounting firms, insurance agencies and other professional services organizations with high-value client data.
A New Level of Impersonation
According to the FBI, SRG actors contact employees while posing as members of an organization's IT team. They may instruct employees to install remote-access tools, grant access to company devices or follow directions that appear legitimate.
If those tactics fail, the group has reportedly sent individuals to company locations in an attempt to gain physical access to systems.
These methods work because they exploit something every organization relies on: trust in internal support teams, familiar processes and the instinct to resolve a perceived technology issue quickly.
Why This Matters for Law Firms and Client-Focused Organizations
Many security awareness programs focus heavily on suspicious emails and malicious links. Those threats remain significant, but this campaign shows how modern cyberattacks increasingly span multiple channels, including phone calls, text messages and face-to-face interactions.
The risk is not limited to a single device or employee. When an attacker gains access, they may move quickly to identify high-value information and use the threat of public disclosure or sale to pressure the organization.
Employees should be especially cautious when anyone unexpectedly requests:
- Access credential
- Multi-factor authentication codes
- Installation of remote-access software
- Changes to system settings or security controls
- Use of external storage devices such as USB drives
Even when a request appears to come from a trusted source, employees should pause and verify it through approved channels before taking action.
What Employees Can Do
Organizations can reduce risk by reinforcing a few practical habits:
- Independently verify requests for technical support through established internal channels.
- Never provide passwords, authentication codes or sensitive information to an unsolicited caller.
- Report suspicious communications immediately to their Information Security team.
- Follow approved processes for granting system access or installing software.
- Question unexpected requests, particularly those that create urgency or pressure.
Make Verification Part of the Culture
Technology remains essential, but employees continue to be the most important line of defense against social engineering attacks. As Steve McMaster, Chief Information Security Officer, notes, "The tactics outlined in this FBI alert are effective because they target people rather than technology. Attackers are counting on employees to trust what appears to be a legitimate request and respond before taking the time to verify it."
That is why awareness, verification and clear internal processes matter. A few moments spent confirming an unexpected request can help prevent the loss of sensitive information, operational disruption, financial loss and reputational damage.
The FBI's warning is a useful reminder that cybersecurity is not solely an IT issue. It is a business issue that depends on awareness, accountability and the confidence to slow down when something does not feel right.
Western Alliance Bank
Western Alliance Bancorporation (NYSE: WAL) is one of the country’s top-performing banking companies and has ranked as a top U.S. bank by American Banker and Bank Director since 2016. Its primary subsidiary, Western Alliance Bank, is a leading national bank for business that puts customers first, delivering tailored business banking solutions and consumer products backed by outstanding, personalized service and specific expertise in more than 30 industries and sectors. With more than $90 billion in assets and offices nationwide, Western Alliance excels at helping businesses of all sizes capitalize on their opportunities to solve today and succeed tomorrow.