Google Warns Hackers Are Targeting Financial Firm Staff via Phone Phishing for Extortion
Google security researchers have revealed that hacking groups are targeting employees at large United States financial and investment firms using direct phone calls to steal sensitive corporate data and demand extortion payments.
What Happened
According to a report released by Google security researchers, cybercriminal groups are actively infiltrating major investment and financial organisations. Rather than relying solely on automated cyber tools, the attackers employ voice phishing, commonly known as “vishing.” Hackers place direct phone calls to employees’ personal mobile devices while posing as colleagues or IT helpdesk personnel.
During these fraudulent calls, attackers persuade workers to enter their company login credentials and multi-factor authentication codes onto spoofed websites. Once internal access is secured, the perpetrators extract sensitive information. Google identified four threat groups involved in these operations—dubbed Falcon, Helix, Pink, and Redact—and tracks them under an umbrella collective named UNC6671. Google noted that these actors operate public leak websites to threaten victims with data publication if extortion demands are not met.
Key Highlights
- Targeted Organisations: While Google did not officially name the victim companies, a Reuters report identified targeted private equity and financial firms including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
- Ransom Demands and Revenue: Threat actors typically demand ransom amounts ranging between $750,000 and $3 million. Google observed approximately $10 million in Bitcoin transferred to a cryptocurrency wallet associated with one of the groups during the early months of the year.
- Method of Attack: Attackers target staff on personal cellphones, posing as internal IT helpdesk staff to bypass protections and acquire multi-factor authentication codes via fake login portals.
- Sector Expansion: The threat actors previously targeted sectors such as real estate, manufacturing, healthcare, insurance, technology, transportation, and hospitality before shifting focus toward high-profile legal and financial entities.
Why This Matters
Google researchers pointed out that focusing on organisations involved in mergers, acquisitions, litigation, and capital deployment allows hackers to acquire highly sensitive corporate and confidential data. This critical information gives attackers significant leverage when demanding extortion payouts, as threat actors publicly state that non-payment will result in published data breaches.
What to Watch Next
Researchers continue to track UNC6671 to determine whether the groups function as independent affiliates, splinter groups, or users of a shared Phishing-as-a-Service platform. The targeted firms named in reports—including Apollo, Blackstone, Bain Capital, and KKR—had not issued responses to requests for comment at the time of reporting.
Frequently Asked Questions
What is voice phishing or vishing?
Voice phishing is a social engineering tactic where attackers make direct phone calls pretending to be trusted figures, such as IT helpdesk personnel or co-workers, to manipulate individuals into sharing sensitive credentials or one-time passcodes.
What data are the hackers attempting to steal?
According to Google, the attackers aim to exfiltrate confidential business records, VIP client information, valuable intellectual property, software source code, and corporate transaction details to maximize their extortion leverage.
Source: TechCrunch, citing research from Google and reporting by Reuters.
