Silent Team, also tracked as Silent and silent_team, is a financially motivated cybercriminal group conducting data-theft extortion. It emerged in public threat tracking in April 2025 and operates within the ransomware and data-leak ecosystem, relying on stolen information and threats of disclosure rather than deploying file-encrypting ransomware in its documented extortion activity. The group has claimed victims including ESP Associates, Fleet Canada Inc., Advanced Simulation Technology, Versa Networks, Cocoon, and Judicare Legal Aid, spanning technology, engineering, aerospace-related businesses, and legal services. Its operations emphasize data exfiltration and leak-based pressure to obtain ransom payments. Silent was recorded with 99 leak-site incidents in May 2026, placing it second in that month's tracked group rankings.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rapidly emerging ransomware group that newly entered the top rankings by incident volume.
Data-theft and extortion operations targeting U.S. legal firms, using callback phishing, phone-based social engineering, remote access attempts, and in-person impersonation of IT staff to gain physical access and steal data without deploying ransomware encryption.
Named as the ransomware group that demanded $13 million in connection with a March 2026 data breach affecting Jones Day.
Ransomware group noted for a large ransom demand against a business-sector legal firm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.