Cybersecurity

Hackers vishing financial firm staff to extort victims, Google says

2 min read

Hackers vishing financial firm staff to extort victims, Google says
Photo: Juanjo Jaramillo · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Hackers are using phone calls to trick employees at major U.S. financial firms into handing over their login credentials, then stealing sensitive data and demanding ransom payments, according to a report released by Google’s security researchers on August 6, 2026. The attackers have targeted private equity giants including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG, as reported by Reuters, though Google did not name the victims directly. The hacking groups, which Google tracks under the designations Falcon, Helix, Pink, and Redact, employ a technique known as voice phishing, or vishing, by calling employees on their personal cellphones and posing as coworkers or IT helpdesk staff to lure them into entering credentials and multi-factor codes on fake websites. Once inside the firms’ systems, the hackers exfiltrate valuable data and then threaten to publish it on dedicated leak sites unless a ransom is paid. The report suggests these groups may all operate under a larger collective that Google calls UNC6671, though it remains unclear whether they are affiliates, splinter groups, or simply share the same Phishing-as-a-Service infrastructure. Google researchers believe this coordinated approach allows the actors to manage multiple extortion brands, compartmentalize operations, conceal the true scale of breaches, and isolate any fallout from failed negotiations. The hackers have previously struck companies in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality, aiming to steal intellectual property, software source code, and sensitive client data. More recently, they have focused on legal and financial organizations involved in mergers, acquisitions, capital deployment, and litigation, a shift that Google says likely reflects a strategy to maximize leverage in extortion demands by targeting high-value corporate and confidential information. One cryptocurrency wallet tied to a hacking group received approximately $10 million in Bitcoin during the first few months of 2026, and the attackers typically demand between $750,000 and $3 million from each victim. The targeted firms did not respond to requests for comment.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.