Google says hackers are calling financial firm employees to hack and extort victims
Google's security researchers have identified hacker groups using old-fashioned phone-call scams, known as "vishing", to breach major US financial and investment firms, aiming to steal sensitive data and extort victims with threats of publication. Reuters reported that targets reportedly include prominent private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG, though Google itself did not name victims. The report highlights that even amid growing concerns about AI-driven cyberattacks, simple social engineering tactics remain highly effective against well-resourced organisations.
Google has dubbed the groups Falcon, Helix, Pink and Redact, and believes they may operate under a larger umbrella collective it tracks as UNC6671, possibly to compartmentalise operations and obscure the scale of breaches. The hackers call employees' personal phones posing as colleagues or IT helpdesk staff, tricking them into entering credentials and multi-factor codes on fake websites, before threatening to leak stolen data via dedicated extortion sites unless a ransom is paid. Google noted that one associated cryptocurrency wallet received around $10 million in bitcoin in early 2026, with typical ransom demands ranging from $750,000 to $3 million, and said the groups have previously targeted manufacturing, healthcare, real estate, tech and other sectors before shifting focus towards legal and financial firms.
- Hackers use phone-call scams to breach major US financial and private equity firms
- Google links groups Falcon, Helix, Pink and Redact to wider UNC6671 network
- Ransom demands range from $750,000 to $3 million per victim