you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / market watch
26 August 2026 market watch 5 min read

Silent Ransom Group doubles its law-firm roster: Troutman Pepper Locke data leaks as unpaid victims climb to 64

The Silent Ransom Group (SRG) has spent 2026 quietly doing something unusual for an extortion crew: publishing more victims without fanfare, and mostly without responses from the victims themselves. Tracking of the group's public leak site shows the number of law firms with unpaid, published data climbing from 38 in April to 48 on June 29, and then to 64 as of August 21, 2026. That is a near-doubling of the roster in roughly four months, all of it involving firms that apparently did not pay or did not negotiate, and much of it unfolding with little public comment from the organizations involved. As DataBreaches.net reported, the latest and largest entry concerns one of the biggest law firms in the United States.

From 38 firms to 64 in four months

SRG's extortion model differs from mainstream ransomware operations in one important respect: nothing gets encrypted. The group steals data, demands payment, and publishes whatever goes unpaid on its leak site, which has operated under the LeakedData brand and the domain business-data-leaks[.]com. Unlike most ransomware brands, SRG hosts that site on the open internet rather than as an onion service, framing each victim entry with claimed revenue figures and download counts for the stolen files. Researchers who track the page counted around 100 victim organizations overall in early June, a figure that includes professional-services targets alongside the law firms. The legal-sector tally specifically moved from 38 in April to 48 by June 29 before reaching 64 on August 21, according to the tracking summarized by DataBreaches.net. Recent SRG listings beyond Troutman Pepper Locke have included firms such as Reminger, Riker Danzig and Mayer Brown, based on third-party threat-intelligence reporting.

Troutman Pepper Locke: tens of thousands of SSNs, and a claimed repeat hit

On August 18, 2026, SRG listed Troutman Pepper Locke, a firm with more than 1,600 attorneys, on its extortion portal, and days later the promised data appeared. According to DataBreaches.net's review of the leak, the published material includes over 64,000 records containing full Social Security numbers alongside names and what appear to be privileged legal documents belonging to the firm's clients. The outlet characterized the exposure as tens of thousands of SSNs, and noted that the firm had not responded to requests for comment at the time of publication. That silence matters, because affected clients currently have no official confirmation, no breach notifications and no guidance, while their personal data sits on a public download page. Unconfirmed but consistent with prior incidents: SRG's own listing statement claims this is the second successful attack on the same firm within a year, stating the first came through a physical intrusion. Reporting from April 2025 described an incident at the firm in which operatives allegedly posed as IT staff, though the firm at the time described only a single compromised laptop. The gap between that characterization and the current leak volume remains unresolved.

The FBI has been warning about exactly this

None of the intrusion techniques on display here are new to federal investigators. As CyberScoop has covered, the FBI has repeatedly warned the legal sector about SRG, including advisories describing callback phishing and vishing calls in which actors impersonate internal IT support to talk employees into installing remote-access software. A May 2025 FBI advisory flagged the group's pivot toward law firms specifically, and subsequent FLASH bulletins detailed follow-up extortion calls placed not just to victims but to their employees and clients. Resecurity researchers have also documented cases of hired operatives physically entering firm offices posing as tech support. Law firms concentrate exactly what these actors want: litigation strategy, intellectual property, merger plans and large volumes of client PII, all held by partnerships whose reputational sensitivity makes rapid payment likelier. Estimated demands have ranged from $1 million to $8 million depending on firm size, per industry reporting earlier in 2026.

A leak site designed to be hard to kill

Part of why the roster keeps growing is infrastructure. Resecurity's June analysis of SRG's DNS infrastructure found the group protecting business-data-leaks[.]com with a fast-flux botnet: the domain resolves through a rotating pool of compromised residential devices across roughly 18 countries, with nearly every observed IP on a different consumer ISP. That design defeats simple IP blocking and makes seizure far harder than for a server in a cooperative jurisdiction, even though the site itself sits on the clearnet where anyone, including journalists and affected clients, can browse it. For context on how the more conventional Tor-hosted leak sites operate, see our overview of ransomware leak sites on onion services; SRG is effectively running the same shaming playbook inverted, trading anonymity for maximum accessibility and pressure. For law firms, the practical takeaways are unglamorous and unchanged: verify IT-support requests out-of-band before granting any remote access, restrict and monitor remote-access tooling, segment client-matter systems from general networks, and prepare disclosure procedures that assume the worst. For clients of firms named on the leak site, the current reality is harsher. With Troutman Pepper Locke publicly silent despite tens of thousands of leaked SSNs, credit monitoring decisions may need to be made on the strength of a threat actor's download counter rather than an official notice.

more notes

all news ›