An archive of thousands of private messages belonging to a Russian cyberextortion crew has turned up on a hidden site, and it lays bare an operation willing to put people inside a victim’s building and to bargain over payments in the millions.
The material was reviewed by Recorded Future News and posted in early October by a source who gave no reason for doing so. Its messages run from August 2025 through September 2026, catalog dozens of targets, and describe operatives, called agents, being directed into United States offices. Cryptocurrency addresses found in the dump were examined by Chainalysis, a blockchain analysis firm, which reported that it could trace them to extortions already documented. Those attacks are attributed to a crew tracked under several names: Chatty Spider, Luna Moth, and the Silent Ransom Group.
Healthcare organizations are exposed to the same playbook, because hospitals and clinics extend the front-desk courtesy this crew abuses with a clipboard or a friendly phone call. Anyone unannounced approaching a clinical workstation should draw attention. The physical intrusion method is well established, having been documented earlier by the FBI when it warned that gang members impersonated IT employees to reach computers.
Files copied onto a flash drive at a New York office were among the incidents a professional firm acknowledged when it sat down with the extortionists, according to the archive, which records how the firm pressed for confirmation that all copies of its data would be wiped.