Google warns Blackstone, Bridgewater, Bain, KKR, TPG, Moody’s of phone hack
Google has warned several major financial firms, including Blackstone and KKR, about a sophisticated vishing campaign by hackers known as UNC6671. The attackers use voice phishing to steal credentials and MFA tokens to exfiltrate data from cloud environments.
Google has revealed that ransom-seeking hackers have targeted dozens of major US financial institutions and businesses in recent weeks, including Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG, and Moody’s. According to a report by Reuters, the attackers used phone calls to trick employees into revealing credentials, then deployed malicious websites tailored to each firm. “Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon,” said Google in a blog post.Google’s findings revealed how hackers operatedIn a blog post, Google said the hackers operate under aliases such as Redact, Pink, Falcon, and Helix, and have recently shifted focus to private equity firms, law practices, and ratings agencies. Some companies reportedly paid ransoms, though Google did not name them. Reuters analysis of 72 malicious websites linked to the campaign showed traps designed for more than 200 companies in the past five weeks.“UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta,” added Google.Human element exploitedCyber experts noted that the attackers rely on low-tech but effective tactics. “Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” said Lee Clark of the Retail and Hospitality ISAC. Google’s Austin Larsen added: “Really, it’s a money thing. They think these firms have sensitive data worth paying to protect.”Beyond Wall Street, firms such as Uber, Zillow, Levi Strauss, and law firms including Paul Hastings and Greenberg Traurig were also targeted. Hedge funds like Point72, Two Sigma, and Citadel were among those approached by hackers.Get the latest technology news and updates. Download the TOI App.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in