Skip to content

Google and the FBI have sounded the alarm after detecting a dangerous tactic used by cybercriminal groups

· 3 min de lectura
falsos empleados ransomware

Google and the FBI have sounded the alarm after detecting a dangerous tactic used by cybercriminal groups: the sending of fake technical support employees to corporate offices to steal information directly from computers.

Google and the FBI detect new ransomware tactic

Cybersecurity teams from Google and the FBI, along with specialists from Mandiant and the Google Threat Intelligence Group, have documented how the criminal group known as Silent Ransom Group (SRG) has intensified this type of physical attack. The criminals pose as authorized technicians, gain physical access to systems, and once inside, steal credentials, install malware, and prepare the ground for ransomware attacks.

The warning from Google and the FBI highlights that this technique combines social engineering, identity theft, and physical access, breaking the idea that digital threats only come through email or the internet.

How fake technical support employees operate

Intelligence reports describe a clear pattern: the group studies the company, collects real names of suppliers and departments, and then sends supposed technicians with well-prepared scripts. In many cases, they arrive with uniforms, fake IDs, and apparently legitimate work orders.

  • They request direct access to critical workstations.
  • They connect their own USB devices or laptops for “diagnosis”.
  • They capture access credentials and sensitive data.
  • They leave backdoors installed for future ransomware attacks.

According to experts, this combination of physical presence and advanced intrusion techniques makes Silent Ransom Group one of the most sophisticated actors in the current landscape.

Google and the FBI warnings for companies

The recommendations from Google and the FBI point to reinforcing the verification of identity of any external technical support personnel. It is emphasized that no technician should have access without prior confirmation with the official provider and the internal IT department.

It is also advised to train employees to recognize warning signs: unexpected changes in maintenance appointments, pressure to quickly access critical equipment, or refusal to verify their identity.

Global impact and risk for Latin America

Ransomware attacks have grown globally, and Latin America has not been left out. Experts point out that service companies, healthcare, finance, and the public sector can be targets of this type of operation. The alert from Google and the FBI aims to prevent these tactics from expanding to emerging markets, where physical access controls are sometimes weaker.

For countries like Dominican Republic, where business digitalization is advancing quickly, this type of warning is crucial to adjust security policies, both in the digital environment and at office entrances.

Key prevention measures recommended

Cybersecurity experts agree with the recommendations from Google and the FBI and propose several immediate measures:

  • Strict protocols for the entry of external personnel.
  • Detailed records of visits and mandatory accompaniment.
  • Multi-factor authentication for critical access.
  • Network segmentation to limit the movement of attackers.
  • Periodic simulations of social engineering to train personnel.

The joint warning from Google and the FBI reinforces a clear message: cybersecurity is no longer limited to the virtual world, and companies must protect themselves from both malicious emails and supposed technicians who knock on the door.

Publicado en: https://orgullodominicano.org/en/google-and-the-fbi-have-sounded-the-alarm-after-detecting-a-dangerous-tactic-used-by-cybercriminal-groups/