They phoned. They screen-shared. Some came in person.
Between January and May 2026, a hacker group tracked as UNC3753 — also known as Luna Moth and Silent Ransom Group — ran a campaign against dozens of U.S. firms in the legal, financial, and professional services sectors, according to Google Mandiant.
The method: vishing (voice phishing — phone calls designed to trick people into handing over access). Attackers called employees pretending to be IT support, using fake pretexts like data migrations or invoice issues. Once they had the target on the line, they convinced them to start a screen-sharing session and install remote monitoring software on their own machine. At that point, the attacker could see and control everything.
From there, UNC3753 searched for and stole proprietary legal agreements, personal records, and financial data. The goal was extortion — pay up, or the files go public.
The detail that stands out: in some cases, attackers showed up physically at victim premises. No keyboard required.
Stolen data included contracts, personal records, and financial files. No ransomware was deployed — this was pure theft and pressure.
What to do: Your IT team will never cold-call you and ask to take control of your screen. If someone calls claiming to be tech support and asks you to install anything or share your screen, hang up and call your IT department back on a number you already know.

