Your IT Help Desk Is Never Going to Call You
Silent Ransom Group is calling US law firms by name, walking attorneys through a fake IT support call that completes data theft in under…
Your IT Help Desk Is Never Going to Call You
Silent Ransom Group is calling US law firms by name, walking attorneys through a fake IT support call that completes data theft in under three minutes. Here’s the five-minute message that breaks the entire playbook.

The associate at an eight-attorney firm in Houston picked up the phone Tuesday at 2:14 PM.
The caller knew her first name. He said he was from the firm’s IT provider. He named the provider correctly.
There was unusual activity on her Microsoft account, he said. They needed to get her connected to support right away. The whole thing would take three minutes.
She put him on speaker. He walked her through opening a browser, going to a short URL, and downloading a small file. The file was AnyDesk, a remote-control program she had heard of. He talked her through the install. He gave her a nine-digit code and asked her to read it back. She read it.
The cursor on her screen moved on its own for a half second, then stopped.
He thanked her and ended the call. Her Outlook still loaded. Her billing software still worked. She went back to drafting a settlement memo.
By 5:30 PM, eighty gigabytes of client files were on a server she had never heard of.
— -
What just happened
The attorney just got hit by Silent Ransom Group, a vishing crew that BleepingComputer reported on June 7 is running dedicated phone campaigns against US law firms. Vishing is the same idea as phishing, but the channel is a phone call instead of an email. Mandiant has confirmed the attribution.
The pitch is short. “We noticed unusual activity on your account. We need to get you connected to support right now.” The target is walked through installing one of a small number of legitimate remote-access tools, usually AnyDesk or Zoho Assist. Once the install completes and the operator types in the access code the employee reads aloud, the attacker has full keyboard-and-mouse control of the workstation.
Data exfiltration starts in parallel and runs in hours.
This is the part that surprises most owners. Silent Ransom Group does not deploy ransomware. The encryptor never runs. Nothing on the network locks. The entire business model is data theft followed by extortion: pay or we publish your client files. For a law firm the math is brutal. Malpractice exposure, client confidentiality, and bar-complaint risk push the extortion demand to three to five times the typical industry multiple.
The phone is now an attack surface in the same way email was a decade ago. Vishing has appeared in three of the last six issues of this newsletter under different operator names. ShinyHunters ran calls against ADT and Udemy in April. The Tycoon2FA and Kali365 phishing kits added phone-based MFA-prompt theft to their menus in May. Silent Ransom Group is the next entry. Same opening move. New specialist.
— -
Why your phishing training didn’t help
Your employees have been taught to watch for sketchy emails. That training is fine, and you should keep doing it. It just was not built for this attack.
Rank what your existing defenses actually do against a Silent Ransom Group call, weakest to strongest.
Email security gateways stop nothing. There is no email.
URL inspection and link rewriting stop nothing. No link is sent.
Antivirus and EDR stop nothing. The thing the user installs is AnyDesk or Zoho Assist, signed by the real publisher, downloaded from the real vendor site. Your endpoint product treats those installers exactly the way it treats Slack and Zoom, because they are software in the same legitimate class.
Multi-factor authentication stops nothing. The attacker never logs in. The employee is already logged in. The attacker is operating that logged-in session as if they were sitting at the same desk.
Phishing-resistant hardware keys stop nothing on this attack. They are still worth having, but the keys protect the login. The attack happens after the login.
The one thing that breaks Silent Ransom Group is the employee never accepting the call’s instructions. If the attorney hangs up at “we need to get you connected to support,” the chain ends. Every other defense in your stack is downstream of that decision. Your job, for this week, is to make sure that decision is the obvious one.
— -
What you can actually do this week
Three actions. All under a day. All under $1,000 combined.
-
Send one message to your entire staff today. Five minutes. Free. Use these words or your own: “Our IT provider will never call you out of the blue to ask you to install software, share your screen, or read out a code. If anyone calls claiming to be IT, hang up. Call [name] at [direct number] before you do anything. This is true even if the caller knows your name, our firm name, or our IT provider’s name.” Email it. Slack it. Print it and tape it to the receptionist’s monitor. This single line breaks the entire Silent Ransom Group playbook.
-
Lock down the remote-access tools you actually use. Thirty minutes. Free. If your firm uses AnyDesk, TeamViewer, Splashtop, Zoho Assist, or ScreenConnect, set a password for unattended access on every machine. Uninstall any copy that is not in daily use. The mechanic that completes the attack is an employee accepting an incoming session prompt. If the tool is not installed, the prompt never appears. If the tool is installed but locked, the attacker needs the password, not just a polite voice on the phone.
-
Ask your IT vendor to block unapproved remote-access installs at the endpoint. Thirty to sixty minutes for them. Free if you already have EDR. Send your IT provider one sentence: “Please block installation of AnyDesk, Zoho Assist, ScreenConnect, ConnectWise Control, and Splashtop on every workstation that does not already have a business reason to run them, and route any future install requests through you.” Every modern EDR product, including Microsoft Defender for Business, can enforce this through an application-control policy. This is the layer that catches the employee who follows the attacker’s instructions despite Action 1.
— -
The harder truth
This week’s ransomware tally is 107 disclosed victims across 32 active groups, the eighth straight week the count has landed between 97 and 107. The tempo is now structural rather than spiky. The Gentlemen took the top spot with 27 victims (25.2% of all activity), replacing the rotation among Qilin, Akira, and DragonForce that defined May. Healthcare snapped back to 14 victims after a one-week pause, exactly the rebound this newsletter predicted on May 25. Seven different ransomware crews contributed to that fourteen.
Silent Ransom Group sits inside that picture, not outside it. The campaign is not aimed at large law firms with general counsel and security operations centers. It is aimed at the three-to-thirty-attorney shop where one person handles billing, IT, and the front-desk phone. Those firms hold trust ledgers, client SSNs, settlement details, sealed records, and matter notes that are catastrophic if published. The criminals figured out that legal practice is the cleanest extortion vertical in the small-business market, and they built a phone team around it.
Next week, the same opening move will be aimed at a different vertical. Vishing crews rotate by industry. Healthcare and accounting are next on the visible roadmap.
The question is whether your team has been told what to do when the phone rings.
— -
If this was useful
I write S6 Ransomware Signal](https://s6-ransomware-signal.beehiiv.com/))**, a free weekly newsletter for small and mid-size businesses without a dedicated security team. Every Monday it covers the week’s most important ransomware and extortion campaigns, what the victim counts actually say about who is being targeted, and one fix you can put in place before your next staff meeting.
This week’s full issue also covers:
- The Check Point VPN zero-day that Qilin was actively exploiting before the patch shipped, with the one-sentence question for your IT provider that tells you whether you need to act today
- A breach at Group GTI, the third-party platform that runs career services for Oxford and several other universities, and what the recurring vendor-route compromise pattern means for the privileged third parties touching your data
- The Microsoft analysis on AI-themed phishing campaigns now running at more than 100,000 emails per day, impersonating ChatGPT and Claude billing prompts, and why your accounts payable team is the one most likely to bite
Subscribe here.](https://s6-ransomware-signal.beehiiv.com/subscribe).**) It is free.
The criminals are picking up the phone now. The advice that worked when they used email is already a step behind.
메타데이터
- post_id
- 42ba5f6e66bb
- slug
- your-it-help-desk-is-never-going-to-call-you-42ba5f6e66bb
- url
- https://medium.com/@s6techllc/your-it-help-desk-is-never-going-to-call-you-42ba5f6e66bb
- canonical_url
- https://medium.com/@s6techllc/your-it-help-desk-is-never-going-to-call-you-42ba5f6e66bb
- author_url
- https://medium.com/@s6techllc
- status
- ok
- fetched_at
- 2026-06-11 06:59:45