Unknown hacking groups are breaking into major U.S. financial and investment firms by calling employees on their personal cellphones and tricking them into handing over login credentials, according to a report published Thursday by Google's security researchers. The attackers, who Google has labeled Falcon, Helix, Pink, and Redact, are stealing sensitive data to extort victims with the threat of making it public. Among the targets are leading private equity firms including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, and TPG, as well as CME Group and Moody's, Reuters reported.
The hackers pose as co-workers or IT helpdesk staff during the phone calls, persuading targets to enter their credentials and multi-factor authentication codes on fake websites—a technique known in the cybersecurity world as voice phishing, or vishing. One cryptocurrency wallet linked to a hacking group received approximately $10 million in bitcoin during the first several months of this year, according to Google. The attackers typically demand between $750,000 and $3 million from their victims. Before concentrating on legal and financial organizations, the groups previously targeted large companies in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors with the aim of stealing intellectual property, software source code, or sensitive client data.
Google researchers believe the different groups may all belong to a larger umbrella collective the company tracks as UNC6671, though it remains uncertain whether they operate as affiliates, splinter groups, or simply share the same Phishing-as-a-Service infrastructure. "We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout," the report states. Several of the groups operate websites where they announce their breaches and threaten to publish stolen data as leverage for extortion—a standard tactic among cybercriminals. One such site warns victims: "We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement."
According to the researchers, focusing on organizations involved in mergers, acquisitions, capital deployment, and litigation may represent a strategy to target high-value corporate and confidential data that maximizes leverage for extortion demands. The shift toward private equity firms suggests the hackers are chasing deals and client information that command bigger ransoms than the intellectual property they pursued in earlier campaigns. Despite advances in AI-powered cyberattacks, the report underscores that crude, old-fashioned techniques like tricking victims over the phone continue to deliver strong results for attackers. The success of vishing campaigns reveals that human vulnerabilities remain easier to exploit than technical defenses, even at well-resourced financial institutions. Firms caught in the crosshairs face a stark choice: pay up quickly and quietly, or risk having their most sensitive data exposed online for competitors and regulators to see.

