FBI Warns of Hackers Posing as IT Staff in Person
FBI Warns of Hackers Posing as IT Staff in Person

The FBI has issued a warning about a hacking collective known as Silent Ransom Group (SRG) that is impersonating IT support staff to gain physical access to company computers. The group, active since 2022, has shifted from remote cyber attacks to in-person tactics, targeting US law firms primarily, with medical and insurance sectors also at risk.

According to an FBI alert, SRG uses IT-themed social engineering calls to gain trust, then sends an individual posing as an IT employee to the firm. Once inside, they insert a storage device into a computer to steal sensitive data, which is later used for extortion via ransom emails threatening to sell or post the information online.

The trend highlights how hackers are resorting to low-tech methods in the face of advanced AI defence systems. While AI is being adopted by defenders, attackers also use AI for voice cloning and deepfakes. However, cybersecurity experts warn that AI alone is insufficient; companies must strengthen physical security and employee verification procedures.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Bogdan Botezatu, senior director of threat research at Bitdefender, noted that the attack's simplicity is its strength, exploiting weak physical security and lack of controls around removable media. He emphasised that cybersecurity failures often begin with basic human error, such as trusting a stranger claiming to be from IT.

Pickt after-article banner — collaborative shopping lists app with family illustration