Cyber Threat Actor: Silent Ransom Group
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
2 incidents |
|---|
Profile
The threat actor known as Silent Ransom Group also operates under the alias SilentRansomGroup. Public reporting identifies the group by these names in connection with cyber incidents targeting legal sector entities. No other aliases are mentioned in the available sources. The actor first came to attention through attacks on prominent United States law firms.
In April 2026 the group was attributed to an intrusion at Jones Day where data belonging to ten of the firm’s clients was released. A month later, in May 2026, Fox Rothschild LLP where data belonging to ten of the firm’s clients was released. A month later, in May 2026, Fox Rothschild LLP faced a lawsuit alleging that a cyberattack by the same actor exposed a plaintiff’s personal information, including a potential Social Security number. Both incidents occurred within the United States, with the Fox Rothschild case filed in the Eastern District of Pennsylvania. The sources describe the events as highlighting cybersecurity risks confronting law firms.
The provided material does not detail specific malware families, initial access vectors, or tooling styles employed by Silent Ransom Group. Consequently, no definitive TTP themes can be extracted from the cited reports. The absence of such technical specifics means any discussion of the actor’s methods would be speculative. Therefore, the profile refrains from asserting particular techniques or tools associated with the group.
Attribution to a state sponsor or a criminal consortium is not presented in the available sources. The actor is described solely as a ransom‑themed group without further linkage to known nation‑state campaigns or organized crime syndicates. No public statements or indictments connect Silent Ransom Group to any governmental entity. As a result, the actor’s affiliations remain unspecified in the current open‑source record.
The Jones Day and Fox Rothschild incidents serve as the primary publicly reported operations attributed to Silent Ransom Group. These cases illustrate the actor’s focus on law‑firm targets and the consequent legal and regulatory repercussions for the victim organizations. The reports note that the attacks prompted reviews of ethical duties, breach‑notification practices, and vendor oversight within the legal sector. No additional campaigns are referenced in the supplied context.
