TechRadar News.
Technology

Silent Ransom’s Unencrypted Data‑Theft Scheme Netted $207 Million from 27 Companies

Silent Ransom’s Unencrypted Data‑Theft Scheme Netted $207 Million from 27 Companies

Leaked internal chat logs from the cyber‑crime group Silent Ransom reveal that it collected $206.95 million from 27 victim firms over roughly a six‑month span, never encrypting the stolen data. The messages, obtained by a cybersecurity outlet, show the attackers relied solely on exfiltrated files to compel payments.

The excerpts appear to come from a private messaging platform the gang used and were handed to researchers after a whistleblower posted them to an encrypted drop site. Analysts argue the logs are genuine, citing timestamps, consistent slang and references to particular ransom talks that line up with previously reported cases.

Silent Ransom’s method illustrates the rising “double extortion” model, where criminals steal sensitive information and threaten to publish it unless a fee is paid. Unlike traditional ransomware that locks files with encryption, this approach skips that technical step, lowering the chance of decryption errors and enabling higher ransom demands based on the perceived worth of the leaked records.

With 27 organizations paying an average of about $7.7 million each, the operation underscores how profitable data theft can become when victims fear damage to reputation, regulatory fines or exposure of trade secrets. Although the compromised firms came from a range of sectors, the leaked chats do not identify them, indicating a wide‑reaching targeting strategy that exploits the steep costs of data breaches across industries.

Security specialists caution that the success of Silent Ransom’s non‑encryption tactic could prompt other groups to follow suit, complicating defenses that have traditionally centered on blocking encryption. Law‑enforcement bodies are said to be examining the logs as part of ongoing probes into transnational ransomware networks, but pinpointing the actors remains difficult because of anonymizing services and cryptocurrency payments.

Following the disclosures, cybersecurity firms are urging companies to bolster data‑loss‑prevention measures, implement continuous exfiltration monitoring and craft incident‑response plans that address the risk of public data release. As investigators piece together the full extent of the scheme, the case highlights the shifting economics of cybercrime, where simply possessing stolen data can yield payouts in the multi‑hundred‑million‑dollar range.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related