ClosedLow impactAI Refreshed

Google and FBI Warn of Ransomware Group Deploying Fake IT Workers for In-Person Hacking

Occurred 1 Apr 2025·Detected 9 Jun 2026·
🇺🇸 United States (advisory origin); global threat scope3 reportsEnded 1 Jul 2026
CyberPolitical RiskPolitical RiskCyberCasualty & Liability

Google and the FBI issued a joint advisory warning that a ransomware group is placing fake IT workers inside target organisations to conduct insider-enabled hacking. Subsequent reporting linked the tactics publicly to the Silent Ransom Group (aka Luna Moth / Chatty Spider / UNC3753), believed Russia-based, which has escalated to physically sending imposters into victim offices — primarily US law firms — to connect USB drives and exfiltrate data for extortion, with dozens of victims reported in early 2026. Separately, CrowdStrike reporting attributes approximately 47% of state-backed cyber intrusions against US tech firms (April 2025–May 2026) to North Korea-linked Famous Chollima using deepfake identities and fake IT worker personas. No specific victims, loss figures, ransom demands, variant attribution, or insurance claims have been confirmed.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. This remains a threat advisory, not a confirmed loss event. No named insureds, ransom demands, or claims activity have been disclosed, so no reserving trigger or pricing action is warranted from the event itself. The Silent Ransom Group angle (physical in-office intrusions at US law firms, data theft/extortion without encryption) and the Famous Chollima angle (fake-IT-worker insider placement tied to state-backed intrusion activity) both expand the cyber attack surface relevant to underwriting — particularly around HR vetting, third-party IT hiring controls, and physical access controls. Cyber syndicates should treat this as a watch signal for insider-threat and hiring-control hygiene; the law-firm targeting has potential Professional Indemnity / cyber aggregation relevance, and physical USB-driven intrusions add a tangible property/crime overlay. No immediate market action is supported.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇰🇵 North Korea🇷🇺 Russia🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts