Cybercriminals are increasingly turning to a surprisingly simple tactic to break into major financial companies: calling employees on the phone and pretending to be trusted colleagues or IT support staff.

Google’s security researchers say several hacking groups have been targeting financial and investment organizations in the United States, attempting to steal confidential information that can later be used for extortion. The attackers reportedly threaten to publish stolen data unless their victims agree to pay large ransoms.

Google has identified four groups involved in the activity, tracking them under the names Falcon, Helix, Pink, and Redact. The company believes they may be connected through a broader operation known as UNC6671, although researchers have not determined whether the groups are affiliates, independent crews, or customers of the same phishing infrastructure.

The attack starts with a phone call

Rather than relying entirely on sophisticated malware or automated attacks, the hackers are using voice phishing, or “vishing.”

Employees receive calls on their personal phones from attackers posing as coworkers, helpdesk employees, or other trusted contacts. The criminals then attempt to persuade the employee to visit a fake website and provide login credentials or multi-factor authentication codes.

Once inside corporate systems, attackers can search for valuable information, including confidential business documents, intellectual property, source code, and sensitive information belonging to wealthy clients.

Google says the campaign has previously affected organizations across several industries, including healthcare, manufacturing, insurance, real estate, technology, transportation, and hospitality.

More recently, however, the attackers appear to have focused heavily on financial and legal organizations. Private equity companies and firms involved in mergers, acquisitions, investments, and litigation can hold particularly valuable information, making them attractive targets for extortion.

Millions in ransom demands

The criminals have established websites where they publicly claim responsibility for attacks and threaten to release stolen information. Google says ransom demands typically range from $750,000 to $3 million.

One cryptocurrency wallet linked to one of the groups reportedly received approximately $10 million worth of Bitcoin during the first few months of 2026, suggesting that the operation has already generated substantial proceeds.

Google researchers believe the multiple hacking brands could represent a coordinated strategy. Operating under separate names may allow the criminals to hide the overall scale of their activity, separate individual operations, and reduce the consequences if one group is exposed.

Several major financial organizations were reportedly targeted, including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. The companies have largely declined to discuss the incidents publicly.

The campaign also demonstrates that advanced AI-powered attacks aren’t replacing traditional social engineering. In many cases, attackers still only need a convincing phone call, a fake login page, and an unsuspecting employee to gain access to valuable corporate systems.

Share.
Leave A Reply

Exit mobile version