Back Mezha Google Warns US Financial Firms About Voice Phishing Extortion Attacks
A familiar phone call can open the door to multimillion-dollar extortion, even inside companies handling the world’s most sensitive financial data.
Based on data from Techcrunch
In an era of increasingly sophisticated cyberattacks powered by artificial intelligence, traditional deception tactics remain effective. Unidentified hacker groups are deliberately targeting major U.S. financial and investment firms to steal sensitive data and blackmail victims by threatening to publish it, Google researchers reported in a report released Thursday.
The victims include leading private investment firms Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
The hacker groups, which Google has designated Falcon, Helix, Pink, and Redact, are using an old method of infiltration: calling employees on their personal phones while impersonating colleagues or technical support staff. The calls are intended to persuade targets to enter their credentials and multi-factor authentication codes on fake websites. In cybersecurity, this practice is known as voice phishing, or vishing.
Some groups also create websites where they publish details of their attacks and threaten to release stolen data as a way to pressure victims into paying a ransom. This tactic is used to coerce targets and obtain financial gain.
We conduct negotiations strictly on professional terms. Publishing your data is never our preferred resolution; it is a consequence of refusing to engage, deliberately delaying, or failing to honor the agreement.
According to the report, some of the groups may belong to a larger consolidated operation known as UNC6671. However, it is unclear whether these are affiliated entities, splinter groups, or the same Phishing-as-a-Service infrastructure being used by all of them.
We believe this most likely reflects a coordinated threat group operating under different extortion brands, possibly to divide its operations, conceal the overall scale of the breaches, and isolate the consequences of negotiations.
The groups’ earlier targets included large companies in the industrial, real estate, healthcare, and insurance sectors, as well as technology, transportation, and hospitality, with the aim of stealing valuable intellectual property, source code, or sensitive data belonging to VIP clients.
In more recent attacks, the perpetrators have focused on legal and financial organizations, particularly private investment firms. “The focus on organizations involved in mergers, capital allocation, and litigation may indicate a strategy of targeting high-value corporate and confidential data to maximize ransom demands,” Google researchers noted.
According to Google, the groups previously targeted organizations across various sectors but have recently concentrated on legal and financial entities. The report also said that a cryptocurrency wallet linked to one of the groups received approximately $10 million in bitcoin over a short period during the year; the criminals typically demanded between $750,000 and $3 million from victims.
Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG did not respond to requests for .
This report highlights that social engineering methods involving voice phishing remain relevant threats to major financial institutions and that companies, cybercrime authorities, and auditing firms need to strengthen their security measures.
You may be interested in these materials:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
