Ransomware Groups Claim Attacks on Moses & Singer and Philippine Savings Bank as New Cyber Threats Surface + Video

Listen to this Post

Featured ImageA New Wave of Ransomware Claims Raises Fresh Alarm

Two organizations from very different sectors have reportedly been named as victims by ransomware groups in a new wave of dark-web activity: New York law firm Moses & Singer LLP and Philippine financial institution Philippine Savings Bank, commonly known as PSBank.

According to a threat-intelligence alert attributed to ThreatMon and circulated on August 2, 2026, the ransomware operation known as Silent Ransom Group allegedly added Moses & Singer to its victim list. A separate alert claimed that another ransomware actor, TheGentlemen, had added Philippine Savings Bank to its list of victims.

At this stage, however, these should be treated as ransomware-group claims rather than confirmed breaches. No independent evidence establishing the scope of either incident was included in the original alert, and the organizations’ own public confirmation was not identified during this review.

That distinction matters. Ransomware leak sites and threat-actor monitoring feeds can provide valuable early warnings, but a listing alone does not prove that an organization was successfully compromised, that data was stolen, or that ransomware was actually deployed.

Two Victims, Two Very Different Targets

The two organizations represent particularly sensitive targets for cybercriminals.

Moses & Singer is a New York law firm whose practice areas include banking and finance, healthcare, technology, intellectual property, litigation, privacy and cybersecurity, among others. Its client base includes businesses and individuals dealing with potentially sensitive legal, financial and corporate information.

PSBank, meanwhile, is a Philippine savings bank offering deposit accounts, loans, digital banking, payment services and other financial products. The bank describes itself as a publicly listed savings bank and says it operates hundreds of branches and more than 500 in-branch and offsite ATMs.

The contrast is striking. One organization holds privileged legal information and confidential client communications, while the other operates financial infrastructure where customer identity, account and transaction information can be extremely valuable.

The Moses & Singer Claim

The first alert attributes the alleged attack against Moses & Singer to the Silent Ransom Group, an actor that has also been associated with the names Luna Moth, Chatty Spider and UNC3753.

The claim is particularly noteworthy because Silent Ransom Group has already attracted significant attention from U.S. authorities and security researchers for its unusual approach to extortion.

In May 2026, an FBI flash report described Silent Ransom Group as an actor that targets organizations through social engineering, including impersonating IT personnel. The FBI said the group has used phone calls and phishing emails to gain access, while in some cases attackers have physically appeared at victim locations posing as IT support.

Silent Ransom Group Does Not Need Traditional Encryption

One of the most important details surrounding Silent Ransom Group is that its operations do not necessarily resemble the classic ransomware scenario in which computers are encrypted and employees suddenly find ransom notes on their screens.

The FBI has described the

That means the Moses & Singer claim should not automatically be interpreted as evidence that the firm’s systems were encrypted.

The real danger, if the claim proves accurate, could instead involve unauthorized access to confidential documents, emails, legal files, credentials or other sensitive information.

Why a Law Firm Is an Attractive Target

Law firms are unusually valuable targets because they often sit at the intersection of multiple organizations.

A single firm may possess contracts, acquisition documents, litigation material, financial records, intellectual-property information, employee information and confidential communications belonging to dozens or hundreds of clients.

For an extortion group, compromising one law firm can therefore create several layers of pressure.

Attackers can threaten the firm itself, its employees, its clients and even counterparties involved in confidential legal matters.

That makes the legal sector especially attractive to groups that specialize in data theft rather than indiscriminate encryption.

The Philippine Savings Bank Claim

The second alert concerns Philippine Savings Bank, or PSBank, which was reportedly added to TheGentlemen’s victim list.

PSBank is a significant financial institution in the Philippines and provides digital and traditional banking services, including savings, checking and time-deposit products, loans, online banking and mobile services. Its website states that the institution is regulated by the Bangko Sentral ng Pilipinas.

A successful compromise of a financial institution could potentially have consequences far beyond the organization itself.

Customer information, employee accounts, internal systems, financial records and third-party connections can all become valuable targets in a broader intrusion.

But once again, the current evidence establishes a claim, not a confirmed compromise.

TheGentlemen Is an Active Ransomware Operation

The second actor is not an unknown name in the ransomware ecosystem.

Threat-intelligence tracking describes TheGentlemen as a ransomware operation that emerged in 2025 and subsequently developed a ransomware-as-a-service model. Other intelligence sources have documented hundreds of claimed victims associated with the group.

The group has been associated with double-extortion tactics, in which attackers allegedly steal information before threatening to publish it if ransom demands are not satisfied.

This approach gives attackers leverage even when an organization can restore its systems from backups.

The Real Weapon Is Often the Stolen Data

Modern ransomware is increasingly about more than encryption.

Backups can allow an organization to recover files. Network segmentation can limit lateral movement. Endpoint detection can sometimes stop an encryptor before it reaches critical systems.

But stolen information is different.

Once sensitive data leaves an

That is why ransomware groups increasingly treat data exfiltration as a central part of their business model.

Why Financial Institutions Remain High-Value Targets

Banks possess precisely the combination of information that cybercriminals value most: identity data, financial information, authentication systems and large networks of customers and partners.

Even when attackers cannot directly access customer funds, stolen internal information can potentially support fraud, phishing, credential theft and social-engineering campaigns.

A bank compromise can therefore create secondary risks long after the original intrusion has ended.

For this reason, any claim involving PSBank deserves careful monitoring even before the underlying incident is confirmed.

A Claim Is Not the Same as a Breach

The most important editorial caution surrounding both reports is simple: being listed on a ransomware leak site does not automatically prove a successful attack.

Threat actors have incentives to exaggerate.

A victim may have been contacted but never compromised. Data may have been obtained from another incident. Old information may be repackaged. In some cases, groups may publish claims before negotiations have concluded.

Independent verification is therefore essential.

The Problem of False or Recycled Claims

The ransomware ecosystem is also filled with examples where public claims require additional scrutiny.

Researchers have noted instances in which ransomware groups allegedly republished or recycled information that had previously appeared elsewhere. Community investigations have also warned that a ransomware listing alone cannot establish how the data was obtained.

This does not mean the current claims are false.

It means that responsible reporting must distinguish between “the actor claims” and “the organization was breached.”

That difference protects readers from misinformation while still allowing them to understand emerging threats.

What the Two Claims Reveal About Ransomware

Taken together, the reports highlight how broad modern extortion operations have become.

The alleged victims span legal services and banking, two sectors with very different technologies and operating models.

Yet both contain information that can be monetized.

This demonstrates that ransomware groups are not necessarily searching for one particular industry. They are searching for organizations where access, data and business disruption can be converted into financial pressure.

Social Engineering Is Becoming a Critical Attack Surface

The Silent Ransom Group case adds another warning: security cannot be reduced to software vulnerabilities.

If an attacker can persuade an employee to install remote-access software, disclose information or allow a supposed technician to access a workstation, sophisticated perimeter defenses can become irrelevant.

The

The attack may begin with a conversation rather than an exploit.

Physical Security Is Now Part of Cybersecurity

The reported tactics associated with Silent Ransom Group are particularly disturbing because they blur the traditional boundary between physical and digital security.

An employee may be trained to identify suspicious email attachments, but may be far less prepared for someone physically appearing in an office while claiming to be an IT technician.

This creates a new security question for organizations: Who is actually authorized to touch a computer?

That question becomes especially important in law firms, financial institutions and other environments where sensitive information is concentrated.

The Importance of Identity Verification

Organizations should treat unexpected IT requests with the same caution normally applied to suspicious emails.

Employees should independently verify technicians, contractors and support personnel through trusted internal channels.

A phone number provided by the visitor should not automatically be trusted.

A badge should not automatically be considered proof of authorization.

And urgency should never replace verification.

What Happens if the Claims Are Confirmed?

If either incident is eventually confirmed, investigators will need to determine several critical facts.

The first question will be how the attackers entered.

The second will be whether privileged credentials were obtained.

The third will be whether data was exfiltrated.

The fourth will be what systems or applications were accessed.

And the fifth will be whether the stolen information has been published, sold or used in subsequent criminal activity.

The Potential Impact on Moses & Singer

For Moses & Singer, the most serious consequences would potentially involve confidential client information rather than operational disruption alone.

Legal documents can contain sensitive commercial negotiations, intellectual property, litigation strategies, financial information and personally identifiable information.

If such material were stolen, the effects could extend beyond the law firm itself.

Clients could face additional exposure, while the firm could be forced to investigate notification obligations, contractual responsibilities and potential regulatory consequences.

The Potential Impact on PSBank

For PSBank, the potential risk profile is different.

A confirmed intrusion could raise questions about customer information, employee credentials, internal banking infrastructure and third-party systems.

Even if core banking systems remained protected, compromised employee accounts or peripheral systems could become stepping stones for additional attacks.

Financial organizations therefore have to treat even apparently limited compromises seriously.

The Broader Ransomware Economy

The ransomware economy has matured into a sophisticated criminal ecosystem.

Operators can recruit affiliates, purchase access, outsource technical services and monetize stolen information.

This means the organization appearing on a leak site may not necessarily have been attacked by the people operating the ransomware brand directly.

Different actors can participate at different stages of an intrusion.

Why Threat Intelligence Still Matters

Despite the uncertainty surrounding individual claims, threat-intelligence monitoring remains valuable.

Early warnings can give defenders an opportunity to search for suspicious authentication activity, unusual data transfers, compromised credentials and unauthorized remote-access tools.

The key is using intelligence as an indicator for investigation, not as unquestioned proof.

A ransomware listing should trigger a response process.

It should not automatically trigger a public declaration that a breach has been confirmed.

Deep Analysis: Commands for Defenders

Command 01 — Treat Every Claim as an Incident Signal

Security teams should immediately log ransomware claims involving their organization and compare the reported timing with authentication, endpoint and network telemetry.

Command 02 — Search for Abnormal Authentication

Review privileged logins, impossible-travel events, new devices, unusual VPN sessions and authentication attempts from unfamiliar locations.

Command 03 — Audit Remote-Access Software

Because Silent Ransom Group has been associated with social-engineering-based access, organizations should investigate unexpected installations or unusual use of legitimate remote-management tools.

Command 04 — Protect Privileged Accounts

Reset potentially exposed privileged credentials and investigate newly created administrator accounts, especially when suspicious activity overlaps with the reported attack window.

Command 05 — Examine Data Movement

Look for unusual outbound transfers, large archive files, unexpected cloud uploads and connections to unfamiliar external infrastructure.

Command 06 — Validate Backups

Backups should be tested rather than merely assumed to exist.

An organization that discovers a breach while simultaneously discovering that its backups cannot be restored has already lost valuable response time.

Command 07 — Segment Critical Systems

Financial and legal organizations should minimize the ability of a compromised workstation or employee account to reach sensitive systems.

Command 08 — Strengthen Human Verification

Employees should know exactly how to verify IT personnel, contractors and support requests.

Command 09 — Monitor External Exposure

Security teams should monitor relevant leak sites and threat-intelligence feeds for signs that organizational data has been published or advertised.

Command 10 — Preserve Evidence

Incident responders should preserve logs, endpoint telemetry, email records, authentication history and relevant network evidence before attackers or automated retention systems erase them.

What Undercode Says:

The Timing Is Significant

The two claims appearing on the same day demonstrate how quickly ransomware intelligence can develop across unrelated sectors.

The Targets Are Strategically Valuable

A law firm and a bank are both information-rich environments, even though their technical infrastructure may look very different.

Silent Ransom Group Is Particularly Concerning

The

Physical Intrusion Changes the Equation

The reported willingness of attackers to impersonate IT personnel means physical security controls can directly affect cyber resilience.

The Moses & Singer Claim Fits a Known Target Pattern

Moses & Singer operates in the legal sector, an industry that Silent Ransom Group has repeatedly targeted according to U.S. authorities.

But Pattern Matching Is Not Proof

The fact that the alleged victim fits the actor’s historical targeting does not independently confirm that the reported intrusion occurred.

TheGentlemen Has Demonstrated Scale

Threat-intelligence sources track TheGentlemen as a highly active ransomware operation with hundreds of claimed victims.

Financial Institutions Face Higher Consequences

A confirmed compromise at PSBank could potentially affect sensitive financial and personal information even if no direct financial theft occurred.

Data Theft Can Be Worse Than Encryption

Encrypted files can potentially be restored.

Stolen information cannot simply be recovered from a backup.

Extortion Has Become Data-Centric

Modern ransomware operators increasingly rely on stolen information to create pressure against victims.

Reputation Is Part of the Attack

Public victim listings are designed to create urgency and reputational pressure.

Fear Is a Criminal Tool

Threat actors understand that uncertainty itself can push organizations toward negotiations.

Claims Can Be Manipulated

Ransomware groups have incentives to make their operations appear larger, more successful and more dangerous.

Recycled Data Is a Real Risk

Previous incidents show why defenders and journalists should investigate whether alleged evidence is genuinely connected to a new intrusion.

Verification Requires Multiple Sources

The strongest confirmation comes from the victim, regulators, investigators or credible independent technical evidence.

Dark-Web Monitoring Has Real Value

Even an unverified claim can provide defenders with an important opportunity to investigate before a threat becomes more damaging.

Banks Should Assume Secondary Attacks

If employee credentials or internal information are exposed, attackers may use them for phishing and fraud campaigns.

Law Firms Should Protect Client Relationships

A law-firm breach can potentially expose information belonging to many unrelated organizations.

Third Parties Matter

Security programs must include vendors, contractors, managed-service providers and remote-access platforms.

Identity Is the New Perimeter

When attackers can impersonate trusted employees or technicians, identity verification becomes as important as network filtering.

Least Privilege Becomes Essential

A compromised ordinary workstation should not automatically provide a path toward sensitive systems.

Network Segmentation Limits Blast Radius

Segmentation can prevent one compromised environment from becoming an organization-wide disaster.

Backups Remain Critical

Even though backups do not solve data theft, they remain essential for recovering from destructive ransomware activity.

Detection Speed Determines Damage

The longer attackers remain inside a network, the more opportunities they have to discover valuable systems and information.

Logging Is an Insurance Policy

Without adequate telemetry, organizations may struggle to determine what happened, when it happened and what information was accessed.

Security Awareness Must Be Practical

Employees need concrete procedures for verifying suspicious support requests rather than generic warnings about “cyber threats.”

Physical Security Belongs in Cyber Plans

The Silent Ransom Group case demonstrates that cyber incident response cannot always stop at the network boundary.

Public Claims Require Calm Responses

Organizations should avoid reacting emotionally to ransomware announcements.

Silence Can Also Be Dangerous

At the same time, dismissing a claim without investigation can allow attackers additional time inside an environment.

The Correct Response Is Verification

Security teams should investigate first, determine the facts and then communicate based on evidence.

Customers Need Accurate Information

If a financial institution is confirmed to have suffered a data breach, customers need clear guidance about what information may be affected.

Clients Need Transparency

If a law firm confirms stolen client information, affected clients may require rapid notification and assistance.

Regulators May Become Involved

Depending on the nature of confirmed data exposure, legal and regulatory obligations could follow.

Ransomware Groups Continue Adapting

The shift toward social engineering, data theft and hybrid physical-digital intrusion shows that attackers are not standing still.

Defenders Must Adapt Faster

Organizations cannot rely exclusively on

The Biggest Warning Is the Uncertainty

The most important fact about

But Unverified Does Not Mean Irrelevant

A claim can be false, exaggerated or accurate—and defenders still benefit from investigating it immediately.

The Final Lesson

The Moses & Singer and PSBank claims are a reminder that ransomware is no longer simply a battle against malicious encryption.

It is increasingly a battle over identity, trust, confidential information, human behavior and the ability to respond before stolen data becomes a weapon.

✅ The Silent Ransom Group Is a Documented Threat Actor

The FBI has publicly identified Silent Ransom Group, also known as Luna Moth, Chatty Spider and UNC3753, and described its data-theft and extortion activity.

✅ TheGentlemen Is a Documented Ransomware Operation

Independent threat-intelligence sources track TheGentlemen as an active ransomware group with a large number of publicly claimed victims.

❌ The Two August 2 Victim Claims Are Not Independently Confirmed

The available evidence supports that ThreatMon reported the two listings, but the material reviewed does not independently establish that Moses & Singer or Philippine Savings Bank were successfully breached, what data may have been stolen, or whether ransomware was deployed.

Prediction

(-1) More Verification Pressure Is Likely

The negative risk is that one or both claims could develop into confirmed data-security incidents, particularly because both alleged victims operate in sectors containing highly valuable information.

Ransomware Claims May Escalate

If either organization refuses negotiations, threat actors could potentially publish samples or additional information as an intimidation tactic.

Secondary Phishing Could Follow

If employee or customer-related information was actually obtained, attackers could use it to construct more convincing phishing and social-engineering campaigns.

Financial-Sector Scrutiny Could Increase

A confirmed PSBank compromise would likely receive heightened attention because of the sensitivity of banking infrastructure and customer information.

Legal-Sector Risks Could Expand

A confirmed Moses & Singer incident could potentially affect not only the firm but also clients whose confidential information was stored or processed by the organization.

The Positive Scenario Remains Possible

The claims may ultimately prove exaggerated, incomplete or unrelated to a successful compromise.

The Best Outcome Is Rapid Confirmation

The sooner the organizations and their security teams establish whether unauthorized access occurred, the sooner customers, clients and partners can receive accurate information.

The Bigger Prediction

Regardless of the final verdict on these two specific claims, ransomware groups will continue moving toward data theft, social engineering and identity-based intrusion because these methods can generate pressure without depending entirely on traditional file encryption.

▶️ Related Video (74% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube