Key facts
- Unknown hacking groups are targeting large financial and investment firms in the US.
- Hackers use voice phishing (vishing) to trick employees into revealing credentials and multi-factor codes.
- The objective is to steal sensitive data for extortion, with demands ranging from $750,000 to $3 million.
- One group's associated Bitcoin wallet received approximately $10 million in the first few months of the year.
- Google researchers believe these groups may operate under a larger umbrella collective, UNC6671.
Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims, Google's security researchers reported. The hackers employ a technique known as voice phishing, or vishing, by calling employees' personal cellphones and impersonating coworkers or IT helpdesk staff to trick them into entering their credentials and multi-factor codes on spoofed websites.
Google identified several hacking groups, including Falcon, Helix, Pink, and Redact, which may all be part of a larger umbrella collective the company tracks as UNC6671. These groups often run websites where they publicize their hacks and threaten to leak stolen data to extort payment. One cryptocurrency wallet associated with a hacking group received approximately $10 million in Bitcoin in the first few months of this year, with typical demands ranging from $750,000 to $3 million.
While specific victims were not named by Google, Reuters reported that leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG are among those targeted. The hackers have previously targeted companies in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors, but have recently focused on legal and financial organizations involved in mergers, acquisitions, and litigation to maximize leverage for their extortion demands.
