Luna Moth Escalates: FBI Alert, Leak Site, $20M Demands

Active since March 2022, the extortion crew known as Luna Moth has run a quiet, repeatable con: send a fake invoice, wait for the target to call the phone number printed on it, and talk them into installing remote-access software. In May and June 2026, the quiet part ended. A leak site listing roughly 100 victims, ransom demands reported as high as $20 million, an FBI FLASH alert and - most striking of all - attackers physically walking into law firm offices mark a sharp escalation for a group that built its reputation on never needing malware at all.
An FBI FLASH Alert Signals a New Phase
On May 26, 2026, the FBI circulated a TLP:CLEAR FLASH report warning that the Silent Ransom Group - one of several names for Luna Moth, alongside Chatty Spider and the Mandiant designation UNC3753 - was actively impersonating IT personnel to break into US organizations. FLASH reports exist to push urgent, actionable indicators out to industry quickly, and the distribution of this one through sector bodies such as the American Hospital Association shows how broadly the bureau wanted the warning to land.
The timing was no accident. The alert arrived in the middle of the group's most aggressive stretch of activity to date, as the crew leaned harder than ever on public-pressure tactics to force victims to the negotiating table.
Dozens of Breaches in Five Months
Google's Mandiant and its Threat Intelligence Group have documented UNC3753 breaching dozens of US professional-services, legal and financial organizations between January and May 2026. The intrusion chain is disciplined and almost entirely human: an invoice-themed email that contains no malicious link or attachment, followed by a phone call in which the attacker poses as internal IT support and guides the victim into installing legitimate remote-access tools such as AnyDesk, Zoho Assist or Microsoft Quick Assist.
Because every step relies on trusted software and a believable pretext, there is often nothing for an email filter or endpoint agent to flag. According to Google's threat intelligence team, once a remote session is established the group moves straight to data theft, in some cases initiating exfiltration of sensitive files in under an hour - with extortion emails arriving as little as 30 minutes after the actors exited the environment. Reporting from The Hacker News underscores how consistently the same playbook has worked across dozens of victims.
The focus on law firms and financial-services organizations is deliberate. These firms hold concentrated troves of confidential client material - deal documents, litigation strategy, personal financial records - where the mere threat of publication creates enormous settlement pressure, no encryption required.
A Leak Site, Three-Day Deadlines and a $20 Million Demand
The group's data leak site, which has existed since December 2024, listed roughly 100 victim organizations by June 2026, with dozens of law firms among them. Victims named on the site are given a three-day deadline to open negotiations before their stolen data is published.
The financial stakes have escalated along with the publicity. Ransom demands reportedly reached $20 million from a single victim in May 2026, and at least 38 law firms are reported to have had client or internal data leaked. Those figures come from secondary analysis and should be treated as reported rather than independently confirmed, but they are consistent with the scale of activity that Mandiant and the FBI describe.
For legal-sector victims, a countdown clock changes everything. Client confidentiality and privilege obligations mean a public leak is not just an IT incident but a potential malpractice and regulatory event, which is precisely the leverage the leak site is designed to create.
The Attacker at Your Front Door
The most unsettling development is physical. Researchers at Halcyon have documented Silent Ransom Group actors posing as IT technicians inside US law firm offices across 2025 and 2026, walking past reception and plugging USB devices directly into workstations.
It is the same pretext that powers the group's phone campaigns - 'I am from IT, and I am here to help' - simply delivered in person. An employee who might hesitate over a suspicious email can still hold the door open for a confident stranger with a lanyard and a toolbag. The channel changed; the con did not.
One Verification Standard for Calls, Screens and Doors
The escalation carries one clear lesson: identity verification for anyone claiming to be IT support has to apply everywhere, not just in the inbox.
- Phone calls. Employees should never install software or grant remote access on the strength of an inbound call. Hang up and call IT back on a published internal number.
- Remote sessions. Allowlist the remote-support tools your organization actually uses, and alert on installations of AnyDesk, Zoho Assist or Quick Assist outside approved workflows.
- Invoices. Treat an unexpected invoice with a phone number as the callback lure it usually is. Route it to finance for verification - never call the number printed on the document.
- Physical visitors. Require appointments, badges and escorts for anyone performing on-site IT work, and give staff explicit permission to challenge unescorted visitors without fear of being penalized for it.
Rehearsal matters more than policy documents here. Security awareness training that covers impersonation pretexts - including phone-based and in-person variants - combined with phishing simulation exercises built on invoice-style lures gives employees a safe place to fail before Luna Moth offers them a real one. Platforms like empowsec let security teams run exactly those scenarios and then target coaching at the specific points where verification breaks down.
Key Takeaways
- Luna Moth escalated sharply in May and June 2026: an FBI FLASH alert on May 26, and a data leak site listing roughly 100 victim organizations by June, dozens of them law firms.
- The money followed the pressure. Ransom demands reportedly reached $20 million from a single victim, and at least 38 law firms are reported to have had data leaked.
- The intrusion chain is nearly malware-free: invoice-lure emails, fake IT-support calls and legitimate remote tools, with data theft initiated in under an hour and extortion emails arriving as little as 30 minutes after the actors exit.
- The group now shows up in person, posing as IT technicians inside law firm offices and plugging USB devices into workstations.
- Apply one verification standard everywhere: no remote access, software installs or building access for 'IT support' that cannot be verified through a known internal channel - whether they arrive by email, by phone or at the front desk.


