Background
In early October 2026, an unidentified party published the internal chat records Luna Moth. DataBreaches.net first reported the leak on October 7, 2026. The site contains Luna Moth’s full operations chat: 5,692 messages (mostly in Russian) from two internal servers, covering roughly 13 months from late August 2025 to late September 2026.
Such leaks are rare. Like the 2025 Black Basta leaks, the data offers valuable insight into how a financially motivated extortion group plans, recruits, executes, negotiates, and adapts. However, what sets this leak apart is that it captures a group that is still active and evolving, not one in decline.
In this briefing note, we build on our earlier profile of Luna Moth (Ransomware in focus: Luna Moth). We outline what the leaked records add to our understanding of the group, and the key takeaways for organizations.
Who is Luna Moth?
Luna Moth, also known Silent Ransom Group (‘SRG’), Chatty Spider and UNC3753, is a financially motivated threat actor first observed in 2022. As we set out in our July 2026 Ransomware in focus article, the group doesn't leverage encryption as part of its attacks. They typically gain initial access through social engineering, notably by posing as IT support staff and convincing targets to hand over remote access to their systems. Once inside the network, Luna Moth follow a familiar playbook: identifying and exfiltrating sensitive data, then extorting the victims by threatening publication.
While most cyber extortion groups target victims indiscriminately, Luna Moth’s operations are heavily focused on the US legal sector. In 2026, around 78% of the group’s known victims were law firms, a far higher proportion than any other major extortion group. In our previous article, we also noted a sharp increase in activity in early 2026. We said it could mean the group had scaled up its operations or added resources; the leaked chats now provide clear evidence of this.
Timeline
- Late August 2025: The earliest messages in the leaked collection, as the group set up new internal infrastructure.
- June 2026: Media reports describe a Russian-linked scheme to recruit people in the US to physically enter law firm offices. The leaked chats show members discussing this coverage.
- September 2026: The group sets up a second internal chat server for a new extortion brand.
- Late September 2026: The latest messages in the collection.
- October 7, 2026: DataBreaches.net publishes an article describing the leak. Copies of the material are understood to have been shared with other media outlets.
The identity and motive of the person behind the leak aren't yet known. S-RM can't yet confirm whether the material circulating so far on the dark web is the full extent of the leak.
Inside Luna Moth
Luna Moth is a centrally managed extortion business. The leaked communications show a structured operation that is closer to a managed criminal enterprise than a conventional ransomware-as-a-service model, where much of the operational activity is outsourced to affiliates. Luna Moth has a small leadership team (fewer than ten individuals) which controls strategy and finances, supported by specialized workstreams for social engineering campaigns, infrastructure, recruitment, and victim communications. Members are paid through a combination of salaries and bonuses linked to successful cases. The group also moves personnel between workstreams based on performance and operational need.
The financial scale of the operation is significant. The leaked records reference at least 27 ransom payments totaling approximately USD 207 million, illustrating the substantial revenues generated by the group's targeted extortion model and the resources available to sustain its operations
Social engineering drives the operation. The leaked material includes a training manual and call script for operators posing as IT staff and shows how carefully the calls are designed. Callers are coached to build familiarity with victims, unsettle them with claims of suspicious activity and then induce them to hand over control of their systems through a remote access tool. 
Figure 1. Anatomy of a Luna Moth vishing call.
The group researches its targets carefully. Many other established cyber extortion groups look to operate at scale, hitting targets indiscriminately. Luna Moth are unusual in their focused pursuit of victims within the legal sector. Members use commercial business-intelligence platforms to build contact lists of executives, IT leaders, and general counsel at target legal firms. Even out-of-office auto-replies help them map out alternate contacts and executive assistants to approach next.
Extortion is personal and relentless. After stealing data, the group goes well beyond sending a demand email. Operators call senior executives directly from short-lived phone numbers, often posing as a third party paid to pass on a message. They set short deadlines and threaten to contact clients and staff. The group is highly conscious of media attention and sees public reporting as an additional pressure mechanism during negotiations. Members openly discuss using previous victims' experiences as cautionary examples in new negotiations.
The group attempted physical intrusions against victims. In the leaked chats, Luna Moth management discuss recruiting people in the US, mainly through online job ads, to enter the offices of target firms posing as IT staff, couriers, or contractors. They also discuss coercing employees through blackmail and surveillance. The physical-access program appears far less mature or consistently successful than Luna Moth’s core social-engineering operation. The archive shows significant investment but comparatively little evidence that the program generated material revenue when compared with the group’s vishing-led extortion campaigns. Luna Moth members complained that many recruits dropped out after initial payments, and at least one was reportedly arrested.
Luna Moth was diversifying its operating model. The chats show group members establishing a new ‘Sleepless Threat’ brand with separate infrastructure and victim-facing communications. Messages associated with that initiative also discuss obtaining pre-existing network access from initial access brokers, providing an alternative to Luna Moth’s established social engineering model. The leaked messages also show Luna Moth’s intent to broaden their targeting under the new brand, to firms within the accounting, insurance, financial services, and healthcare sectors. The discussions around Sleepless Threat are an important reminder of the ease with which cybercriminal brands can overlap, or be reconstituted quickly with the same personnel, making clear attribution a persistent challenge.
Targets now include the defense sector. Some of the conversations move beyond financial extortion into state-level espionage. Members discuss gathering information on US defense manufacturers and trying to recruit military personnel to provide sensitive information. However these plans seem aspirational rather than showing clear intent.
The group fears law enforcement and tries to evade it. The chats show how even seemingly robust cybercrime operators are always looking over their shoulder. Luna Moth members repeatedly discuss the arrests of associates, avoiding countries with extradition agreements, keeping cryptocurrency wallets separate for each victim, and changing communication accounts after suspected law enforcement infiltration.
Structure

Figure 2. Assessed Luna Moth organizational structure. The figure reflects responsibilities and workstreams described in the leaked communications.
Key takeaways
- Payment is never a guarantee of privacy. Established extortion groups have a clear incentive to uphold commitments made during negotiations. A group that fails to do so would lose its reputation as a reliable brand, and legal counsel, forensic firms and cyber insurers would quickly stop sanctioning payments. However, the Luna Moth Files show that victims who pay can still be exposed through unpredictable leaks, which can occur outside of law enforcement operations. The Luna Moth chats refer to dozens of organizations whose incidents may have been resolved privately, and they indicate that its members may retain copies of data outside the negotiator's direct control. Luna Moth and other established groups may not deliberately breach settlements, but their victims should not rely on a successful negotiation to keep data secure.
- Certain sectors may be singled out by extortion groups based on the data they hold. Luna Moth targets organizations whose value lies in the confidentiality of their clients' data, with reputational pressure as the main lever of extortion. While Luna Moth largely settled on victims in the legal sector, their extortion model applies to any sector built on client confidentiality such as accounting, insurance, and financial services.
- Social engineering is an ever-present threat. Traditional RaaS operations use targeted social engineering (such as vishing) sparingly, as it is hard to achieve the scale offered by other methods which require less effort and are easier to automate (such as exploiting software vulnerabilities across internet-facing devices). However for groups like Luna Moth who are prepared to be more selective, social engineering is a reliably effective technique that is hard to stop with technical controls alone.
What does this mean for Luna Moth?
The BlackBasta leaks came after the group had largely stopped operating. The Luna Moth files, by contrast, have become public at a time when the group is operating at full capacity, with its leaders seeing this as their most successful period and actively investing in their capabilities. The leak may cause short-term disruption, such as replacing infrastructure and accounts or slowing recruitment. However, S-RM assesses that the group will most likely continue operating, possible under a new brand, rather than disband. Indeed, the discussions around ’Sleepless Threat’ as described above demonstrate Luna Moth’s leadership was already exploring this possibility.
Guidance for former victims
Former victims of the Luna Moth group who are not expecting their incident to be public, or who are looking to assess their level of exposure within the leaked data collection are recommended to take the following actions:
- Proactively review or engage a specialist to conduct an investigation into the leaked chats to identify information associated with your organization.
- Monitor the deep and dark web for references to your organization and data to support early identification of publicly exposed information.
General mitigation guidance
Organizations seeking recommendations to protect themselves from extortion groups such as Luna Moth, are recommended to action the following checklist of mitigating actions:
- Set up a verification process for unexpected IT-support contact. Employees should hang up and call back on a known internal number before granting any remote access.
- Restrict and monitor remote-access tools. Block unapproved tools and alert on new installations.
- Enforce phishing-resistant MFA on all VPN and remote-access gateways, and review privileged accounts regularly.
- Monitor for unusual data transfers, especially to personal cloud storage.
- Brief reception, building security, and facilities teams on in-person impersonation tactics.
- Prepare executives and assistants for extortion calls, with a clear escalation path to incident response.
- Test incident response plans against data-theft extortion scenarios, not just encryption-based ransomware.
These insights are derived from our analysis of a copy of the leaked communications, open sources, and S-RM's own incident data. Please contact S-RM for additional information about the leaks and remediation advice.
Edited by Tom Crooke