October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

FBI Warns Law Firms About Luna Moth Data-Theft Extortion Attacks

Luna Moth/Silent Ransom Group targets law firms with fake IT support, remote-access abuse and data-theft extortion. Here is how the campaign works and what firms should do before, during and after an attempted intrusion.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI has warned that Silent Ransom Group (SRG)—also tracked as Luna Moth, Chatty Spider, and UNC3753—is repeatedly targeting U.S. law firms with social-engineering attacks that steal confidential data and demand payment. The operation often avoids encrypting systems: attackers impersonate IT staff, obtain remote access, copy files from endpoints and cloud repositories, and threaten to expose or sell them.

The FBI’s original Private Industry Notification was dated May 23, 2025. The threat remained active in 2026: the FBI’s alerts index listed a May 26, 2026 warning, while Google Mandiant reported a campaign affecting professional, legal, and financial organizations from January through May 2026.

Who Luna Moth is

SRG, Luna Moth, Chatty Spider, and UNC3753 are names used by the FBI and Mandiant for the same or closely associated financially motivated activity cluster. The FBI says SRG has operated since 2022 and consistently targeted U.S. law firms since spring 2023. Mandiant places UNC3753 activity at least as early as March 2022.

The FBI warning focuses on law firms, although it also identifies medical and insurance companies as targets. Mandiant has documented activity across professional, legal, and financial services, so law firms are a principal focus rather than necessarily the group’s only victim sector.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

FBI Private Industry Notification (May 23, 2025) · Google Mandiant analysis (June 5, 2026) · FBI cyber-alerts index

Why law firms are attractive

A single firm may hold litigation strategy, settlement positions, merger documents, privileged communications, personally identifiable information, financial records, intellectual property, and information about many clients and counterparties. That concentration gives criminals several ways to pressure a firm, its clients, and its business partners without disabling the firm’s systems.

How the intrusion works

The campaign combines ordinary-looking messages, persuasive telephone calls, legitimate software, and sometimes physical impersonation. Mandiant says targets may be selected using publicly listed employee contact information.

1. An invoice or subscription pretext

Earlier operations sent messages about a small subscription charge, renewal, or invoice and supplied a phone number to cancel or resolve it. The caller then directed the employee to a remote-access or system-management tool. More recent messages may contain no malicious link or attachment at all.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

2. A caller posing as IT or security staff

A follow-up caller may claim there is an urgent security issue, a data migration, or an invoice problem. The employee is asked to join a screen-sharing session, install or run a support utility, or leave a session available. Caller ID, display names, branding, and support portals are not proof of identity.

3. Remote access and file discovery

Mandiant has observed abuse or attempted abuse of Zoom, Microsoft Teams, Microsoft Terminal Services, Quick Assist, AnyDesk, Bomgar, Zoho Assist, and SuperOps RMM. These are legitimate products. The danger is an unapproved session or installation authorized through deception.

Once inside, the operator may search local files, network shares, virtual desktops, OneDrive, email, and legal-document repositories such as iManage. In some investigated incidents, searches and data staging began in under an hour, and the sequence from first contact to theft and extortion occurred within one business day.

4. A possible in-person follow-up

The FBI described fake IT personnel visiting a firm, claiming to image a computer, fix a security issue, or create a local backup, then connecting removable storage to an endpoint. Mandiant said similar physical incidents were possibly linked to UNC3753 but lacked enough forensic evidence for formal attribution. The FBI observation and Mandiant qualification should not be conflated.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What attackers take

  • Client files and legal agreements
  • Personally identifiable and financial information
  • Local files and mapped network shares
  • OneDrive and other cloud folders
  • Virtual-desktop data
  • Documents in legal document-management systems, including iManage repositories

The FBI identified WinSCP and Rclone as file-transfer tools used in the activity. Their presence alone does not prove compromise; both are legitimate utilities. Effective defense requires software inventory, execution controls, logging, and review of unusual transfers rather than a blacklist of product names.

How extortion follows

This is data-theft extortion, not necessarily encryption ransomware. Traditional ransomware locks systems and demands a decryption key. Luna Moth/SRG-style operations copy information and use the threat of exposure as leverage; encryption may not occur.

Mandiant reported extortion emails arriving as soon as approximately 30 minutes after attackers left an environment in some cases. Notices commonly demanded a response or negotiations within three days and threatened to contact employees, clients, partners, or journalists. The group has also threatened publication on the LEAKEDDATA site. These are reported tactics, not guaranteed steps in every incident, and a threat does not prove that every stolen archive will be published.

Warning signs employees should recognize

  • An unexpected subscription, invoice, renewal, or account-charge message
  • A phone number supplied in an email for billing or IT support
  • An unsolicited caller claiming to be the firm’s helpdesk
  • Pressure to install remote-access or screen-sharing software
  • A request to share a screen or leave a remote session running
  • Instructions to use an unfamiliar website or self-destructing note service
  • An unannounced technician or a visit without a scheduled work order
  • A request to connect a USB drive or copy files for a supposed backup
  • Unusual requests to open OneDrive, mapped drives, document-management systems, or email
  • A ransom message containing screenshots or a partial file listing

Verification rule: never authenticate an IT request through the same phone number, email thread, or chat session that initiated it. End the interaction and use a separately known internal number, directory entry, or ticketing system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What to do after a suspected interaction

  1. Stop. End the call and remote session; do not continue negotiating or demonstrate access.
  2. Isolate carefully. Disconnect the affected endpoint from networks if the incident plan permits. Do not casually power it down, because volatile evidence may be lost.
  3. Verify help. Contact internal IT or the managed-service provider through an independently obtained channel.
  4. Preserve evidence. Keep emails, phone numbers, caller IDs, chat transcripts, browser history, installers, endpoint alerts, and a timeline of actions.
  5. Revoke access with guidance. Disable suspicious sessions and rotate exposed credentials or tokens after forensic direction.
  6. Scope the exposure. Check local drives, network shares, cloud storage, email, document-management platforms, and backups.
  7. Activate the response plan. Bring in breach counsel, the cyber insurer, and an incident-response provider according to policy requirements.
  8. Report. Contact the local FBI Cyber Squad and submit information to the Internet Crime Complaint Center (IC3) while preserving technical evidence.
  9. Handle demands through professionals. Do not assume payment guarantees deletion. Counsel, the insurer, law enforcement, sanctions screening, and a qualified extortion specialist should guide any negotiation or payment decision.

Controls firms should put in place

Verify people, not just messages

  • Require a ticket or work order before remote or physical support.
  • Use out-of-band confirmation for unusual requests.
  • Require photo identification, visitor logging, and continuous escorting for technicians.
  • Train reception and office managers to verify dispatch details with the supposed provider.
  • Prohibit unattended remote access unless explicitly approved and logged.

Mandiant recommends restricting unauthorized remote-management and support utilities, using application-control policies such as Windows Defender Application Control or comparable controls, and alerting on new RMM or screen-sharing installations.

Control endpoints and legitimate tools

  • Maintain an approved software inventory and limit administrator privileges.
  • Use application allowlisting or equivalent execution controls.
  • Restrict portable executables and monitor WinSCP, Rclone, browser uploads, and cloud-transfer activity.
  • Review Quick Assist, Teams, Zoom, and other remote-control capabilities for approval, MFA, logging, and session limits.
  • Do not rely on blocking one product: attackers can use built-in services or substitute another legitimate utility.

Protect cloud and document repositories

  • Audit OneDrive, SharePoint, iManage, other document systems, network shares, and email.
  • Use conditional access so sensitive systems accept only managed, corporate-owned devices.
  • Alert on bulk downloads, unusual staging, external sharing, and new forwarding rules.
  • Apply least privilege and segment high-value client matters from general administration.

Prepare recovery and extortion response

  • Keep offline or logically isolated, preferably immutable, backups.
  • Test restoration for cloud data, document-management platforms, SaaS systems, and local infrastructure.
  • Maintain emergency contact lists and communications channels outside the potentially compromised environment.
  • Review breach-notification, client-communication, and media procedures with counsel and the insurer.

The FBI’s preparedness guidance is available in its November 7, 2023 Private Industry Notification.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this warning does—and does not—mean

The warning does not mean AnyDesk, Teams, Zoom, WinSCP, Rclone, or every other named utility is malware. It means a legitimate tool becomes dangerous when an attacker persuades an employee to authorize it outside normal controls.

It also does not mean every law firm or every physical incident is attributable to one confirmed operator. The FBI documents the in-person tactic, while Mandiant qualifies attribution in related cases. Nor do backups solve data-leak extortion by themselves: they aid recovery, but access monitoring, segmentation, and data minimization address stolen information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Where commercial security services fit

Firms without a security operations team may evaluate 24/7 managed detection and response, incident-response retainers, Microsoft security controls, and cyber-insurance coverage. Relevant capabilities include endpoint and identity monitoring, RMM-session detection, cloud and document-repository monitoring, rapid escalation, forensic investigation, and extortion support.

Microsoft Defender for Endpoint and Microsoft Intune are most natural for firms already standardized on Microsoft 365, Entra ID, Windows, and related administration. Potential MDR or response providers include Mandiant, CrowdStrike, and Arctic Wolf. These services improve detection and response but do not replace independent identity verification, visitor controls, least privilege, or tested procedures.

When reviewing cyber insurance, ask whether the policy covers data theft without encryption, notification and defense costs, social-engineering exclusions, panel-vendor requirements, consent before negotiations, MFA and backup warranties, sublimits, and waiting periods. No product or policy can guarantee that a convincing caller will not reach an employee; the strongest buying criteria are verification, application control, cloud monitoring, human escalation, and contractual response readiness.

Reporting and ongoing updates

Because the FBI listed a further SRG warning on May 26, 2026 and Mandiant observed activity through May 2026, firms should treat this as an active threat pattern rather than a closed 2025 event. Maintain a relationship with the local FBI field office, rehearse the first-hour checklist, and update controls whenever the firm changes its helpdesk, remote-support, cloud, or document-management stack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Treat unsolicited IT support as an identity-verification event, not a routine helpdesk request. A fast, verified stop-and-escalate process—backed by application control, cloud monitoring, visitor security, and an exercised incident plan—is the most practical defense against Luna Moth’s data-theft extortion model.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.