- Chainalysis identified cryptocurrency addresses in a suspected Silent Ransom Group data leak connected to millions of dollars in ransomware payments.
- The leaked materials, published on a website called “The Luna Moth Files,” reportedly contain internal communications, ransom demands, operational documents, and cryptocurrency wallet addresses.
- One of the identified wallets was associated with a $10 mn ransom payment collected in mid-2026, although the authenticity of the broader leak remains unverified.
A suspected leak of internal data belonging to Silent Ransom Group (SRG), a cyber extortion operation associated with attacks on major law firms, has revealed cryptocurrency addresses linked to millions of dollars in ransomware payments, according to blockchain analytics firm Chainalysis.
Chainalysis disclosed its findings on October 7 after an unidentified party published what it claimed were internal records belonging to the group. The materials included cryptocurrency wallet addresses, communications and information about alleged ransom demands.
SRG has been associated with cyberattacks targeting law firms, where attackers steal confidential information and demand multimillion-dollar payments in exchange for withholding the data from public disclosure.
In May, the Federal Bureau of Investigation warned that SRG was conducting targeted attacks against legal organizations, using stolen information to pressure victims into paying substantial ransoms.
According to the FBI, the group’s methods include contacting specific employees by telephone or email and, in some cases, approaching them in person. These efforts are intended to gain access to employee computers and subsequently compromise corporate networks.
The group has also been linked to alleged cyber incidents involving prominent US law firms, including Fox Rothschild and Jones Day, according to earlier Reuters reporting.
The latest disclosure emerged after an unidentified party established a website called “The Luna Moth Files” earlier this week. The website purported to expose internal SRG records, including chat logs, documents describing the group’s activities, alleged ransom demand amounts and dozens of cryptocurrency wallet addresses.
Chainalysis nevertheless identified connections between several cryptocurrency addresses disclosed in the leak and ransomware transactions previously documented through its blockchain investigations.
Reuters said it could not independently establish the authenticity of the published documents or verify the website’s claims.
In an October 7 post on X, the firm reported that certain SRG-linked wallet addresses appearing in the materials were associated with millions of dollars in ransom payments received from victims.
Some of the disclosed addresses matched cryptocurrency wallets that Chainalysis had been tracking before the alleged internal records became publicly available.
One address was connected to a $10 mn payment collected by SRG from a victim in mid-2026, according to the blockchain investigations firm.
The matching addresses provided a link between parts of the newly released information and cryptocurrency transactions that Chainalysis had independently identified in earlier investigations.
The findings do not establish the authenticity of the entire collection of documents published on “The Luna Moth Files.” They do, however, confirm that certain cryptocurrency addresses included in the alleged leak correspond to ransomware payments previously tracked by Chainalysis.









