The Law Firm Data Theft looked like an IT support session

How UNC3753 turned a believable support story into remote access, data theft, and extortion.

by Gene Reich

September 9, 2026

It could start with an invoice. Mandiant found that UNC3753 often used an invoice-themed email from an actor-controlled consumer account. The message carried no link or attachment, so nothing looked dangerous. The email did not deliver an attack. It delivered context. It planted a small worry, so that when the phone rang, the employee was primed to accept that something needed fixing and a caller had arrived to fix it.

An IT call that became access

The call did the conversion. From January through May 2026, Mandiant investigated a campaign by UNC3753, also known as Silent Ransom Group, against dozens of organizations across professional, legal, and financial services in the United States. The attackers gathered employee contact details, often from public websites, then called posing as internal IT or security staff. Because the earlier email suggested a problem, the caller did not sound like a stranger but like the response. The employee was not asked to defeat a control but to help, and helping was the intrusion.

To the employee, the next step looked routine: open Teams or Quick Assist and let support investigate. To UNC3753, those clicks were the entry. The tools performed exactly as designed, initiating the remote session they were built to create, for a person whose authority was never verified. In some cases they had the employee install remote-management software such as AnyDesk, extending control beyond a single call. The FBI noted such campaigns leave few artifacts, because the software is legitimate and antivirus has little reason to flag it. When the employee joined from a personal device, the attacker pivoted through it into the corporate virtual desktop. Cooperation had turned into access.

The FBI’s May 2026 warning shows how little an attacker needs to look legitimate. A familiar support request and an employee willing to help can be enough to turn trust into access.

From access to extortion in hours

Access alone was not the objective. Because the session ran with the employee's permissions, the attacker moved like an authorized user, and that reach became the path into the firm's document stores. Mandiant found that searches, staging, and theft could begin within an hour, while many intrusions ran from first contact to extortion within a business day. It searched local and cloud storage, then pivoted into legal platforms such as iManage, pulling tax records, client agreements, and personal data into staging. Staging became transfer. In one intrusion, 1.7 gigabytes went to a Google Drive account before another 14.4 gigabytes left through WinSCP. UNC3753 generally did not encrypt systems. It took the files, threatened to expose or sell them, and its extortion email could arrive within thirty minutes of leaving.

When the firm recognized the support session as an intrusion, its data had already been exfiltrated. For a law firm, that loss carries pressure beyond the data. A legal repository can hold confidential client information, transaction records, and commercially sensitive material entrusted to the firm. ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized access to information relating to client representation, and Formal Opinion 483 treats the theft of material client data as a breach that can carry response and notification duties. UNC3753 pressed on that exposure, threatening to reach the firm's clients unless it was paid.

The same story reaches the office

When the remote version failed, the attackers did not abandon the pretext. They sent someone to perform it in person. The FBI's May 2026 FLASH advisory reported that Silent Ransom Group sometimes sent an individual to a victim's office, claiming to need physical access to image a device or make a backup for the same invented problem. Once near the machine, that person tried to transfer data onto an external drive or USB device. The delivery had changed while the deception had not. Mandiant assessed these physical incidents as likely associated with UNC3753 but stopped short of formal attribution, because evidence was limited and some cases were not followed by extortion. Remote or in person, the interaction still rested on one unproven claim.

Verification has to run both ways

That claim was the failure the campaign depended on. The firm could authenticate the employee, but the employee could not authenticate the supposed technician, while the identity check ran in one direction. Multi-factor authentication strengthens a login. It does not prove that an unexpected caller represents IT. Awareness training helps, but it asks the employee to detect a deception UNC3753 built to pass. The answer is not to make every employee a better lie detector. It is to stop treating human judgment as identity verification. Before the screen share begins, whoever requests it must prove who they are. Traceless Verify is built for that moment. From the chat or ticket where the request lives, an employee can initiate a bidirectional identity check and record the result before granting screen sharing or remote control. Knowing the firm would no longer stand in for proof of employment.

Verification is the first decision point, not the entire defense. It works beside endpoint policies that restrict unauthorized remote-management software, interactive screen control, and removable storage, and beside monitoring that flags unusual searches, bulk downloads, and transfers to outside services. Those controls limit or detect what happens if a check is skipped. Verification prevents the first authorization from being granted on trust alone. The email may explain why IT is calling, but it should never prove that IT is calling.

Prevent social engineering attacks

Start with one integration, validate quickly, and expand across your environment.