Google warns hackers are calling financial firm staff to extort victims

Original: Google says hackers are calling financial firm employees to hack and extort victims

Why This Matters

Coordinated vishing attacks against top-tier financial firms signal a growing extortion threat to regulated industries.

Google researchers revealed that multiple hacking groups are targeting major U.S. financial and investment firms using voice phishing (vishing) calls, tricking employees into surrendering credentials to steal sensitive data for extortion. Victims reportedly include Apollo, Blackstone, KKR, and Moody's.

Google's security researchers published a report on August 6, 2026, detailing a campaign by multiple hacking groups targeting large U.S. financial and investment firms. The groups, dubbed Falcon, Helix, Pink, and Redact by Google, use voice phishing (vishing): calling employees' personal cellphones while impersonating co-workers or IT helpdesk staff, then directing targets to spoofed websites to capture credentials and multi-factor authentication codes.

Reuters identified victims as including prominent private equity and financial firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG. The groups operate public extortion websites threatening to publish stolen data unless ransoms are paid. One site message read: "The publication of your data is never our preferred resolution; it is the consequence of refusal to engage."

Google believes the groups may all operate under a broader collective tracked as UNC6671, possibly sharing Phishing-as-a-Service infrastructure. Google said the activity likely reflects "a coordinated group of threat actors operating multiple public extortion brands" to compartmentalize operations. Beyond finance, the groups have previously targeted manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors.

Source

techcrunch.com — Read original →