All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Google: Hackers use phone calls to extort financial firms

Created at 6 Aug · 7:51 PM1 source↑ Market-relevant
IN SHORT

Unknown hacking groups are targeting major financial firms by using phone calls to trick employees into revealing credentials, aiming to steal sensitive data for extortion, according to Google's security researchers. The groups, potentially operating under a larger collective, have extorted victims for millions in Bitcoin.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$10 millionBitcoin received by one hacking group's wallet
$750,000 to $3 milliontypical ransom demand
fourhacking groups identified by Google

Who's Involved

Google
security researchers who reported on the hacking groups
Falcon, Helix, Pink, Redact
hacking groups identified by Google
UNC6671
larger collective of threat actors tracked by Google
Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME
leading private equity firms reportedly targeted by hackers
Google: Hackers use phone calls to extort financial firms

↳ Why This Matters

The sophisticated use of basic social engineering tactics like vishing by organized hacking groups highlights a persistent and evolving threat to sensitive corporate data, even within highly secured financial institutions. The scale of potential financial and data loss, coupled with the increasing sophistication of extortion tactics, poses a significant risk to the financial sector and its clients

Key facts

  • Unknown hacking groups are targeting large financial and investment firms in the US.
  • Hackers use voice phishing (vishing) to trick employees into revealing credentials and multi-factor codes.
  • The objective is to steal sensitive data for extortion, with demands ranging from $750,000 to $3 million.
  • One group's associated Bitcoin wallet received approximately $10 million in the first few months of the year.
  • Google researchers believe these groups may operate under a larger umbrella collective, UNC6671.

Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims, Google's security researchers reported. The hackers employ a technique known as voice phishing, or vishing, by calling employees' personal cellphones and impersonating coworkers or IT helpdesk staff to trick them into entering their credentials and multi-factor codes on spoofed websites.

Google identified several hacking groups, including Falcon, Helix, Pink, and Redact, which may all be part of a larger umbrella collective the company tracks as UNC6671. These groups often run websites where they publicize their hacks and threaten to leak stolen data to extort payment. One cryptocurrency wallet associated with a hacking group received approximately $10 million in Bitcoin in the first few months of this year, with typical demands ranging from $750,000 to $3 million.

While specific victims were not named by Google, Reuters reported that leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG are among those targeted. The hackers have previously targeted companies in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors, but have recently focused on legal and financial organizations involved in mergers, acquisitions, and litigation to maximize leverage for their extortion demands.

Frequently asked questions

Voice phishing, or vishing, is a cyberattack technique where hackers use phone calls to trick individuals into revealing sensitive information, such as login credentials or financial details, often by impersonating legitimate entities.

While initially targeting various sectors like manufacturing, real estate, and tech, the hackers have recently focused on financial and legal organizations, particularly private equity firms involved in high-value corporate transactions.

The hackers steal sensitive data and then threaten to publish it online unless a ransom is paid. Some groups maintain websites to publicize their hacks and issue these threats.

What Happens Next

01Google continues to monitor the activities of the UNC6671 collective and its associated groups.
02Financial firms are expected to enhance their cybersecurity measures against vishing attacks.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Hackers are targeting large financial and investment firms in the US.
The goal is to steal sensitive data for extortion.
Google identified hacking groups dubbed Falcon, Helix, Pink, and Redact.
These groups use voice phishing (vishing) to trick employees into revealing credentials.
Some groups publicize hacks and threaten data leaks to extort victims.
Google believes these groups may be part of a larger collective, UNC6671.
The hackers have previously targeted manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors.
More recently, legal and financial organizations, including private equity firms, have been targeted.

Sources

T1
Google says hackers are calling financial firm employees to hack and extort victimsTechCrunch

Related Stories

OpenAI Details AI Agents' Covert Coordination During Hugging Face Breach
6 Aug · 6:31 PM
Hacker pleads guilty to stealing data from over 165 Snowflake customers
6 Aug · 5:16 PM
Meta AI model breached third-party system during testing
6 Aug · 2:11 AM
China-linked LightSpy spyware targets victims in 13 countries
6 Aug · 7:51 PM
Meta AI model breached another company during security test
5 Aug · 10:32 PM