Cybersecurity teams from Google and the FBI have identified a worrying trend in the activity of ransomware groups: sending fake technical support employees to victims’ offices to steal information directly from computers.
According to a report published by the Mandiant and Google Threat Intelligence Group teams, the criminal group known as Silent Ransom Group has intensified its attacks, combining traditional phishing and spoofing methods with physical intrusions from January to May of this year, affecting dozens of entities.
Fake workers and physical access to systems
The Google report reveals that the Silent Ransom Group has resorted to the presence of impostors posing as IT support staff. These individuals enter offices, connect USB devices to employees’ computers, or help other group members establish remote connections to extract confidential information. The stolen data includes contracts, Social Security numbers, and financial and tax records.
We recommend reading: Google will pay 920 million dollars a month to SpaceX in exchange for computing capacity
According to Google and the FBI, fake technicians use USB drives and remote access tools to extract confidential information. (Illustrative Image Infobae)
An FBI spokesperson confirmed to TechCrunch that there are multiple cases in which individuals have managed, or attempted, to gain physical access to the offices and devices of target companies under the guise of technical personnel. This modality represents a significant escalation compared to traditional attacks, where criminals rarely went in person to the affected locations.
ADVERTISING
Extortion methods without encryption
Unlike classic ransomware attacks, the Silent Ransom Group does not always encrypt victims’ information. Instead, it uses its own website to threaten to publish stolen data if they do not receive payment. The hackers first contact victims directly via email to demand the ransom. “In case of ignorance or lack of agreement, we will notify your employees, partners, and clients, after which we will publish your data,” they wrote to one of the affected companies, according to the Google report.
This extortion strategy, which skips file encryption but threatens the public exposure of sensitive information, has become a common practice among criminal groups, seeking to maximize pressure on victims.
Tactics also include phishing emails and phone calls to manipulate employees and gain access to systems. (Europa Press)
Social engineering and telephone manipulation
The report details that the group also uses more conventional methods, such as phishing emails, follow-up phone calls, and social engineering techniques to access systems. The cybercriminals pose as the company’s IT support team, convincing employees to participate in screen-sharing sessions or to install applications under the pretext of resolving security issues or participating in supposed data migration projects.
During these interactions, attackers verbally guide targets to provide remote access or download applications that allow hackers to bypass company security controls, using tools such as Zoom or Microsoft Teams.
A growing and sophisticated threat
Mandiant‘s Chief Technology Officer, Charles Carmakal, explained to TechCrunch that they have investigated cases where attackers have planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks. Google recommends that companies strengthen personnel verification and training in the face of new social engineering threats. (Illustrative Image Infobae)
Although most data breaches occur remotely through malware or digital spoofing, recent incidents show a trend toward mixing digital and physical techniques, which represents a significant evolution in the sophistication of cybercriminals.
The FBI and Google recommend that companies strengthen their personnel verification protocols and raise awareness among their employees about these new attack methods, which combine digital manipulation with physical intrusion to access critical information.





