Hackers vishing financial firm staff to extort victims, Google says
Hackers are using phone calls to trick employees at major U.S. financial firms into handing over their login credentials, then stealing sensitive data and demanding ransom payments, according to a report released by Google’s security researchers on August 6, 2026. The attackers have targeted private equity giants including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG, as reported by Reuters, though Google did not name the victims directly. The hacking groups, which Google tracks under the designations Falcon, Helix, Pink, and Redact, employ a technique known as voice phishing, or vishing, by calling employees on their personal cellphones and posing as coworkers or IT helpdesk staff to lure them into entering credentials and multi-factor codes on fake websites. Once inside the firms’ systems, the hackers exfiltrate valuable data and then threaten to publish it on dedicated leak sites unless a ransom is paid. The report suggests these groups may all operate under a larger collective that Google calls UNC6671, though it remains unclear whether they are affiliates, splinter groups, or simply share the same Phishing-as-a-Service infrastructure. Google researchers believe this coordinated approach allows the actors to manage multiple extortion brands, compartmentalize operations, conceal the true scale of breaches, and isolate any fallout from failed negotiations. The hackers have previously struck companies in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality, aiming to steal intellectual property, software source code, and sensitive client data. More recently, they have focused on legal and financial organizations involved in mergers, acquisitions, capital deployment, and litigation, a shift that Google says likely reflects a strategy to maximize leverage in extortion demands by targeting high-value corporate and confidential information. One cryptocurrency wallet tied to a hacking group received approximately $10 million in Bitcoin during the first few months of 2026, and the attackers typically demand between $750,000 and $3 million from each victim. The targeted firms did not respond to requests for comment.
Sources
- TechCrunchSecondary
Related
LightSpy spyware targets victims in 13 countries, including US
Hacker pleads guilty to stealing data from 165+ Snowflake customers
Hackers target 30 US water systems via exposed controllers
Meta AI model hacks outside system during cybersecurity test
OpenAI AI agents hack Hugging Face via secret message board
OpenAI Atlas browser flaw allowed WhatsApp spam to all contacts
Security pro hacks North Korean hackers, finds 1,640 firms breached
BMC flaws expose thousands of servers to remote backdoor attacks
Trending now
- Franco Baresi funeral draws huge crowds in Milan at 66
- Roman Space Telescope plaque installed with 1.35M names
- Spotify hits 300 million Premium subscribers
- Palantir jumps 16% on 149% commercial revenue surge
- Mistral raises $2B at $13.5B valuation as Europe seeks AI sovereignty
- Jony Ive's first OpenAI gadget is a hockey puck-sized smart speaker
- PUNCH Predicts Solar Storm Arrival Within 30 Minutes in First Test
- Stanford AI designs new viruses with 50+ amino acid changes
Comments
No comments yet. Be the first.