Google Warns: Hackers Call Finance Staff to Extort Millions – Claril Noticias

Major US financial and investment firms, including Blackstone and Bain Capital, have been targeted by hacking groups using phone calls to steal sensitive data and extort millions, according to a Google security report published on Thursday.

Even in an era dominated by AI-driven autonomous cyber threats, traditional social engineering tactics remain highly effective. Cybercriminals are successfully breaching high-profile institutions by tricking employees into compromising their own security credentials.

How the “Vishing” Attacks Target Financial Giants

While Google’s threat intelligence team did not explicitly name the affected organisations, Reuters reported that the victims include elite private equity and financial firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.

To infiltrate these secure networks, the malicious actors—identified by Google under the monikers Falcon, Helix, Pink, and Redact—rely on voice phishing, or “vishing”. This involves placing direct phone calls to the personal mobile phones of employees. Masquerading as colleagues or IT helpdesk support staff, the hackers manipulate targets into entering their login credentials and multi-factor authentication (MFA) codes on fraudulent, spoofed websites.

Inside the Extortion Tactics of UNC6671

Once inside, the hackers exfiltrate highly confidential data. Several of the identified groups operate public leak sites to pressure victims into paying hefty ransoms under the threat of releasing their proprietary information.

Image Credits:Google /

The professionalised tone of these extortion portals is particularly striking. One site states: “We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honour an agreement. Respond promptly and in good faith, and the matter is resolved without further incident.”

Google’s security researchers, who detailed the operations in a newly released report, suggest these distinct hacking groups might belong to a single, broader cybercrime syndicate tracked as UNC6671. It remains uncertain whether these groups operate as independent affiliates, splinter factions, or simply share a common “Phishing-as-a-Service” infrastructure.

According to the report, this setup likely reflects a coordinated group of threat actors running multiple public extortion brands. This strategy may be designed to compartmentalise operations, mask the true scale of their breaches, and contain any fallout from ongoing negotiations.

Strategic Targeting and Multi-Million Dollar Ransoms

This cyber syndicate has a history of targeting diverse industries, including manufacturing, real estate, healthcare, insurance, technology, transport, and hospitality. In those instances, the primary objective was the theft of valuable intellectual property, software source code, or highly sensitive VIP client data.

However, the recent shift towards legal and financial institutions, particularly private equity firms, points to a calculated evolution in strategy. By focusing on organisations deeply involved in mergers, acquisitions, capital deployment, and active litigation, the hackers aim to steal high-value corporate intelligence to maximise their leverage during extortion demands.

The financial scale of these operations is immense. Google revealed that a single cryptocurrency wallet linked to one of the threat groups received approximately $10 million in bitcoin during the first few months of this year alone. Typically, the syndicate demands ransom payments ranging from $750,000 to $3 million from each victim.

When contacted for comment regarding the breaches, Laurie Bischel, a spokesperson for CME Group, declined to provide a statement. Representatives for Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s, and TPG did not respond to inquiries.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *