Skip to main content

Health-ISAC Hacking Healthcare 6-18-2026

This week, Health-ISAC®‘s Hacking Healthcare® examines the evolution of a cyber threat actor that now attempts to gain physical access to a victim’s systems to escalate privileges and exfiltrate data. We break down who the threat actor is, how they operate, and then outline recommendations for physical security in the action and analysis section.

As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)

PDF Version:

 

Text Version:

Welcome back to Hacking Healthcare® !

FBI Warning Reiterates Cybersecurity’s Physical Component 

Late last month, the United States’ Federal Bureau of Investigation (FBI) released a FLASH report detailing the data exfiltration activities of the Silent Ransom Group (SRG).[i] [ii] While data theft and extortion by cybercriminal groups is not new or unique, the group’s willingness to physically access and compromise victims is a good reminder that cybersecurity isn’t limited to cyberspace.

Who Are SRG?

The FBI acknowledges that the SRG has been active as an independent entity since at least 2022, although threat intelligence companies such as CrowdStrike indicate they may be a Russian-based outgrowth of the Wizard Spider/Trickbot threat actor.[iii] [iv] Reports suggest they are a financially motivated criminal group who notably “conduct data theft and extortion operations without relying on traditional ransomware encryption.”[v] Rather than use encryption, the FBI reports that they “typically seek rapid access to victim systems, immediate data exfiltration, and extortion through threats of public disclosure or sale of stolen data.”[vi]

To accomplish their goals in the past, SRG has used a variety of schemes, including phishing emails and phone calls. In 2022, Palo Alto Networks’ Unit 42 noted that the group conducted highly organized campaigns and had “significantly invested in call centers and infrastructure that’s unique to each victim.”[vii]

Evolution to Physical Access

SRG group appears to be back on the radar of threat intelligence and law enforcement groups due to a campaign running from January through May of this year, “targeting dozens of organizations across professional, legal, and financial services in the United States.”[viii] While voice phishing and other common social engineering techniques are noted, the more remarkable aspect of this new campaign is SRG’s willingness to pose as an employee of the victim’s IT department.

According to the FBI report, if SRG failed to attain access through a remote desktop session, they “[sent] a threat actor to the victim’s location to gain access to insert a storage device into the victim’s computer” often by “telling the victim they needed to image the device or create a backup file to address potential impacts from the phishing email.”[ix] At this point, SRG could either escalate privileges or physically exfiltrate data through an external hard drive or USB stick.

The FBI and other law enforcement entities continue to seek information about this group and its activities.

 

Action & Analysis
**Included with Health-ISAC Membership**

 

[i] https://www.ic3.gov/CSA/2026/260526.pdf

[ii] Also known as Luna Moth, Chatty Spider, and UNC3753

[iii] https://www.ic3.gov/CSA/2026/260526.pdf

[iv] https://www.crowdstrike.com/en-us/adversaries/chatty-spider/

[v] https://www.ic3.gov/CSA/2026/260526.pdf

[vi] https://www.ic3.gov/CSA/2026/260526.pdf

[vii] https://unit42.paloaltonetworks.com/luna-moth-callback-phishing/

[viii] https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms

[ix] https://www.ic3.gov/CSA/2026/260526.pdf

[x] https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/physsafeguards.pdf

[xi] https://www.ic3.gov/CSA/2026/260526.pdf

[xii] https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms

[xiii] https://405d.hhs.gov/cornerstone/hicp

[xiv] https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf