Google has uncovered a series of cyberattacks targeting major financial and investment firms in the United States, where hackers are using voice phishing, or “vishing,” to trick employees into handing over login credentials and multi-factor authentication codes.
The campaign aims to steal sensitive corporate data and extort victims by threatening to publish the stolen information.
According to Google’s security researchers, the attackers contact employees on their personal mobile phones while pretending to be co-workers or IT support staff. During the calls, victims are directed to fake login pages where they unknowingly enter their usernames, passwords, and multi-factor authentication codes, allowing the hackers to gain access to company systems.
Although Google did not identify the affected organizations, Reuters reported that the campaign has targeted several prominent financial firms, including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
Google tracks the threat actors under names including Falcon, Helix, Pink, and Redact. The company believes these groups may all operate under a broader threat cluster known as UNC6671, although it remains unclear whether they are affiliated groups, separate teams, or simply share the same phishing infrastructure.
Once inside a company’s network, the attackers steal sensitive business information and then attempt to extort victims by threatening to leak the data publicly. Some of the groups operate dedicated leak websites where they publish details of successful breaches and pressure organizations into paying ransoms.
Google said the same threat actors have previously targeted companies across manufacturing, healthcare, insurance, transportation, hospitality, technology, and real estate. More recently, their focus has shifted toward financial institutions and legal organizations, where confidential information related to mergers, acquisitions, investments, and litigation can significantly increase the pressure on victims to pay.
The company estimates that one cryptocurrency wallet linked to the hacking operation received around $10 million in Bitcoin during the first few months of this year. Individual ransom demands typically range from $750,000 to $3 million, highlighting the financial scale of the operation.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Google’s findings show that despite advances in AI-powered cyberattacks, traditional social engineering techniques such as voice phishing remain highly effective. By exploiting human trust rather than software vulnerabilities, attackers continue to successfully breach high-profile organizations and steal valuable corporate data.





