Cyber Attackers Target Financial Firms, Using Sophisticated Voice Phishing Tactics to Steal Data
A wave of high-stakes cyber attacks has hit several major hedge funds and private-equity firms in recent weeks, with the attackers using voice phishing tactics to trick employees into handing over sensitive corporate login credentials. The attacks are linked to an extortion group known as UNC6671, which is associated with the notorious BlackFile campaign.
According to reports from Reuters and Bloomberg, at least five major financial organizations were targeted, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. In each case, the attackers used voice phishing (vishing) tactics to contact employees on their personal mobile phones, claiming that they needed to enroll in passkeys or update multi-factor authentication settings.
But these calls were not legitimate helpdesk inquiries – instead, they were attempts by hackers to gain access to corporate systems. Once inside, the attackers use automated tools to steal data from cloud services such as Microsoft 365 and Okta, deleting security notifications and password-reset emails along the way. The goal is clear: to extort money from these high-stakes organizations.
Google’s Threat Intelligence Group (GTIG) has been tracking this activity as UNC6671, which has diversified its extortion operations under various public brands, including Redact, Pink, Helix, and Falcon. According to GTIG principal threat analyst Austin Larsen, “GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands.”
The BlackFile campaign first emerged in February 2025, targeting retail and hospitality organizations with data theft attacks. But in July of this year, the group shifted its focus towards private-equity firms, hedge funds, major law firms, and financial-rating agencies. Between January and May 2026 alone, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets.
The sophistication of these attacks is clear: victims are directed to domains impersonating their company that host adversary-in-the-middle phishing kits designed to steal credentials and session cookies in real-time. Once inside the system, the attackers can access all linked cloud platforms with just a single set of login credentials.
This wave of attacks highlights the ongoing threat posed by sophisticated cyber actors. While security teams are doing their best to stay ahead of the game, it’s clear that these attackers will continue to evolve and adapt their tactics as needed.
So what can you do? The most effective way to prevent these types of attacks is to test your defenses thoroughly – but not just once or twice a year. Conduct regular breach and attack simulation tests on all layers of your security infrastructure to ensure that your SIEM and EDR rules are up-to-date and effective.
Source: Bleeping Computer — 2026-08-06