Google and FBI Warn of Ransomware Group Deploying Fake IT Workers for In-Person Hacking
Google and the FBI issued a joint advisory warning that a ransomware group is placing fake IT workers inside target organisations to conduct insider-enabled hacking. Subsequent reporting linked the tactics publicly to the Silent Ransom Group (aka Luna Moth / Chatty Spider / UNC3753), believed Russia-based, which has escalated to physically sending imposters into victim offices — primarily US law firms — to connect USB drives and exfiltrate data for extortion, with dozens of victims reported in early 2026. Separately, CrowdStrike reporting attributes approximately 47% of state-backed cyber intrusions against US tech firms (April 2025–May 2026) to North Korea-linked Famous Chollima using deepfake identities and fake IT worker personas. No specific victims, loss figures, ransom demands, variant attribution, or insurance claims have been confirmed.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. This remains a threat advisory, not a confirmed loss event. No named insureds, ransom demands, or claims activity have been disclosed, so no reserving trigger or pricing action is warranted from the event itself. The Silent Ransom Group angle (physical in-office intrusions at US law firms, data theft/extortion without encryption) and the Famous Chollima angle (fake-IT-worker insider placement tied to state-backed intrusion activity) both expand the cyber attack surface relevant to underwriting — particularly around HR vetting, third-party IT hiring controls, and physical access controls. Cyber syndicates should treat this as a watch signal for insider-threat and hiring-control hygiene; the law-firm targeting has potential Professional Indemnity / cyber aggregation relevance, and physical USB-driven intrusions add a tangible property/crime overlay. No immediate market action is supported.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts