Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”
Members of a Russia-based cyberextortion gang plotted to send operatives into U.S. law firms, kidnap business executives and even recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News.
The archive, posted to a bespoke .onion site in early October by an unidentified source who did not state a motive, contains thousands of messages from August 2025 to September 2026.
In those messages, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.” Some of the named organizations have not publicly acknowledged a breach.
The archive mixes apparent records of real extortion with brainstorming sessions, abandoned plans, boasting and violent fantasies. Recorded Future News could not verify whether the most extreme schemes were ever attempted.
However, parts of the cache have been corroborated independently. Blockchain analysis firm Chainalysis examined cryptocurrency addresses contained in the leak and said it could tie them to known extortions by the Silent Ransom Group, which is also tracked as Luna Moth and Chatty Spider. The company cautioned that it could not “speak to the totality of claims” documented in the archive.
The FBI has also documented the group’s most unusual tactic for a Russian extortion group: recruiting what the gang calls “agents” to physically infiltrate victims’ offices. A flash alert earlier this year warned that members of the Silent Ransom Group were posing as IT personnel to gain physical access to computers.
In one negotiation shared in the chats, a law firm’s representative told the extortionists that the firm knew an individual had entered its New York office and copied files onto a flash drive.
The firm said its executives had authorized $1 million to settle the demand but wanted proof that every digital and physical copy of its information would be destroyed, citing evidence that the LockBit ransomware gang had failed to delete data belonging to victims who paid.
Telegram recruitment
The internal conversations show members plotting for months about how to get their “agents” into firms’ offices. One participant suggested buying delivery uniforms and insulated bags. “We buy these insulated bags and uniforms for agents,” he wrote, before outlining a pizza delivery ruse in which an operative would get through reception by delivering pizza and then pose as an IT worker in the main office itself.
Another proposed creating custom masks modelled on real lawyers, while a different member suggested purchasing smart glasses for an agent posing as a client to record the inside of an office.
An earlier shopping list included a $3,200 printer with ultraviolet capabilities and holographic materials for producing identification cards. Expenses mentioned in the archive include funds sent to forgers, including one in New York.
Nothing in the archive shows whether schemes like the pizza delivery ruse or lawyer masks were successfully used. The broader tactic of sending impostors into offices, however, matches the FBI’s account.
The group’s physical access model depended on finding people willing to do the work, not unlike the disposable agents recruited by Russian and Iranian intelligence agencies.
According to the messages, the group recruited these “agents” through paid Telegram advertisements disguised as ordinary job listings, including nightclub promotion, courier work and security. The ads appear to target Russian-speakers.
The chats show the recruitment process was messy. A roster lists agents by numbered codes and city, with one entry describing a 17-year-old as ready to work while noting that the recruit was underage. The name of another channel appears to indicate that one of the group’s agents had been caught in Chicago.
The group’s apparent leader estimated in February that only one in 10 recruits proved usable, calling it the operation’s “conversion” rate. Another member described the process as a conveyor belt. Some recruits disappeared after receiving money or backed out at office entrances, according to the messages. Others were sent on paid test assignments.
It is unclear whether every recruit understood the ultimate purpose. In one conversation, a member suggested fully explaining the scheme only “to those who we trust fully.”
The leaders regularly referenced these recruits with contempt, including in racist terms. They also discussed tracking the agents themselves in case they stole from the group or went to the FBI.
Pipeline management
The victims were managed with the traditional structure of a normal sales pipeline, with entries progressing from the “chat” stage to “offer,” “contract” and finally “gold.”
In one negotiation, a $100,000 opening offer was mocked as “missing a zero.”
Subsequent entries rose through $500,000, $1.5 million, $2.25 million, $3 million and $3.5 million before the records listed a $6 million contract and then “gold.”
Across the dozens of firms marked “gold,” the archive records roughly $200 million in claimed settlements. Those are the group’s own figures, which could not be independently verified.
About 50 organizations, mostly law firms, appear in the records. Several have publicly disclosed cyber incidents this year, while others have made no public statement.
The chats covered extremely coercive ways of obtaining information, with discussions about senior lawyers and executives — who were routinely called “oldies” — including proposals to follow them, learn their routines and, in one exchange, photograph the school-age child of one of the targets as leverage.
Other conversations proposed a fake escort website and a sexual blackmail scheme, kidnapping executives or their relatives, and forming a “punishment” group to intimidate agents or people accused of cheating the group.
Members of that channel debated whether the group should use real or fake weapons. Nothing in the archive shows those plans were carried out.
Military targeting
The discussions in places move beyond law firms. In April, the group’s leader raised the prospect of targeting someone he described as a senior employee at a major military contractor who worked with the U.S. Army.
In the conversation, he noted that a military company could not simply be treated like an ordinary ransom victim and said the “monetization” would have to be different.
Another user replied that the money could come from the Russian Ministry of Defense, although it is unclear whether the suggestion was sincere. The user ended the message with a laughing emoticon before saying he was going to bed.
The archive contains no evidence that the Russian Defense Ministry contacted the group, commissioned an operation or paid for one.
However, a separate chat channel created in May was more explicit about recruiting U.S. sailors through gay bars near naval bases, to obtain secret information about the movements of “submarine-based nuclear forces.”
The group began collecting information about bases and nearby establishments. Days later, one user wrote, “we’ll beat the Yanks with their own weapon.” Nothing in the messages shows that U.S. service members were recruited or that any military or nuclear information was obtained.
Russian state-linked entities appear elsewhere in the archive in a looser collection of contacts and boasts. One user wrote that he had met a Wagner-linked veteran who had fought in Africa and Ukraine, whom he proposed they work with.
Discussions about the members’ operational security included the leader warning a senior colleague against using iPhones, claiming American authorities could “listen, read and watch the cameras whenever they want.”
The group also studied arrests of associates and discussed traveling through countries they believed presented lower extradition risks, such as Ethiopia, while bemoaning the exposure of jurisdictions such as Dubai to U.S. legal interdictions.
As recently as last month, when the archive concluded, the group talked about relaunching itself under the brand Sleepless Threat. “The ultimate goal is to become a social movement or a cult,” a senior user wrote in April, explaining that the aim was for Americans to believe in the group’s ideas and steal valuable information “without being asked.”

Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79