VMTech
Discuss a project

Google identifies vishing extortion activity targeting US finance firms

Google identifies vishing extortion activity targeting US finance firms

Google security researchers have identified a set of hacking groups using phone-based social engineering to breach large financial and investment firms in the United States and steal data for extortion. The groups, dubbed Falcon, Helix, Pink and Redact, typically demand between $750,000 and $3 million, while a cryptocurrency wallet associated with one group received about $10 million in Bitcoin in the first months of the year.

Reuters reported that the firms affected include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG. Google did not name the victims in its report, and the companies did not respond to Reuters’ requests for comment.

Phone calls used to capture credentials and MFA codes

The intrusion method is voice phishing, or vishing. Attackers call employees on personal mobile phones and impersonate colleagues or IT helpdesk staff. During the call, they seek to persuade the target to enter credentials and multi-factor authentication codes on spoofed websites.

The technique relies on a familiar security weakness: an employee may regard a live caller as more credible or urgent than an unsolicited message. The campaign therefore combines impersonation, credential theft and the collection of authentication codes rather than exploiting a newly disclosed software flaw.

Google’s findings reinforce the risk from phishing operations that abuse trusted services and familiar workflows. The theft of Facebook accounts stolen through Google AppSheet phishing illustrates how attackers can exploit a recognised platform to obtain account access, while the current activity shifts the initial contact to a telephone call and the target to sensitive corporate systems.

Extortion brands may be part of a broader operation

Some of the groups operate websites that publicise compromises and threaten to publish stolen information if a victim does not pay. One site states that data publication is a consequence of refusing to engage, stalling or failing to honour an agreement.

Google assesses that Falcon, Helix, Pink and Redact may be part of a larger collective tracked as UNC6671. It remains unclear whether they are affiliates, splinter groups or users of the same Phishing-as-a-Service infrastructure. Google said the pattern most likely reflects coordinated actors operating multiple public extortion brands to compartmentalise operations, conceal overall breach volumes and isolate negotiation fallout.

Before focusing more recently on legal and financial organisations, the actors had targeted manufacturing, real estate, healthcare, insurance, technology, transportation and hospitality businesses. Google said their objectives included valuable intellectual property, software source code and sensitive VIP client data. It noted that organisations involved in mergers, acquisitions, capital deployment and litigation may hold corporate and confidential information that provides greater leverage in extortion demands.

Business implication

Financial organisations should ensure employees know that no helpdesk caller should request credentials or multi-factor codes for entry on a website, and should establish a separate verification route for unexpected support calls. Testing that procedure against personal-phone vishing scenarios can help turn a simple rule into an operational response.

#cybersecurity#vishing#phishing#finance
Open analytics
On the site 1 views
min read 4 07.08.2026
Instagram

Google identifies vishing extortion activity targeting US finance firms

Open the post on Instagram ↗