
vishing extortion Google says a set of hackers has been using an old but effective tactic to break into large U.S. financial and investment firms: phone calls to employees, fake login pages and pressure to hand over credentials and multi-factor authentication codes. In a report published Thursday, the company’s security researchers said the goal appears to be theft of sensitive data that can later be used for extortion.
vishing extortion
Google ties the activity to several hacker brands
In its report, Google said the activity is being carried out by groups it tracks under the names Falcon, Helix, Pink and Redact. The company said the groups are targeting financial and investment firms in the United States, but it did not identify the victims by name.
Reuters reported that among the companies affected are major private equity and financial firms including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG. Google did not confirm those names in its report, and the firms did not broadly comment on the claims.
The groups are not relying on advanced malware or autonomous systems to get in, according to Google. Instead, they are using voice phishing, commonly known as vishing, by calling employees on their personal cellphones and pretending to be co-workers or IT help desk staffers. During those calls, the attackers try to persuade targets to enter their usernames, passwords and multi-factor authentication codes into spoofed websites.
Why the method still works
The approach is old-fashioned, but that is part of what makes it effective. The researchers’ description suggests that the attacks are built around social engineering rather than technical exploitation, taking advantage of trust, urgency and confusion. Even with increased security awareness across the sector, phone-based impersonation remains a practical way to bypass safeguards if an employee is convinced to approve a login attempt or reveal a one-time code.
Google’s report fits a broader trend in cybercrime: simple human manipulation can still be more reliable than complex automated attacks. The company noted that the groups appear to be focusing on organizations where access to confidential records, business strategy or deal-related documents could create immediate leverage.
Extortion appears central to the campaign
According to Google, some of the groups operate public websites that showcase hacked data and threaten to publish stolen information if victims refuse to pay. That style of public naming-and-shaming has become a common extortion tactic in cybercrime, especially when attackers want to increase pressure without needing to deploy destructive ransomware.
One site cited by Google framed negotiations in professional terms and warned that publication of data would follow if the target refused to engage, delayed too long or failed to honor an agreement. The message on that site said:
“We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” read one of the sites. “Respond promptly and in good faith, and the matter is resolved without further incident.”
That language is notable not because it is subtle, but because it reflects how extortion groups increasingly present themselves as if they were operating a business. Google’s researchers said that threat actors like these can use stolen data to maximize pressure on victims who may be especially concerned about confidentiality, deal flow and reputational damage.
Google says the groups may be connected
The company also said the four branded groups may not be fully separate. Google believes they could be part of a larger umbrella collective it tracks as UNC6671. The researchers said it is not yet clear whether the groups are affiliates, splinter groups or simply users of the same Phishing-as-a-Service infrastructure.
In the report, Google offered this assessment:
“We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” read the report.
If accurate, that structure would help explain why the campaign appears under multiple labels while sharing similar tactics. It would also allow the operators to spread risk across different identities, making it harder for defenders to see the full scale of the activity or link separate incidents together quickly.
Targeting high-value sectors
Google said the same hacking groups have previously gone after large companies in manufacturing, real estate, healthcare and insurance, as well as technology, transportation and hospitality firms. In those cases, the attackers were looking for what Google described as “valuable intellectual property, software source code, or sensitive VIP client data.”
More recently, the researchers said the groups have shifted toward legal and financial organizations, including private equity firms. Google said that concentration may not be accidental.
“Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands,” the company’s researchers wrote.
That makes the campaign especially relevant to firms that handle market-sensitive transactions or legal disputes. Documents tied to acquisitions, financing, litigation and portfolio management can carry substantial value to attackers, not only because of the data itself but because of the pressure it can create if leaked.
Money trails and ransom demands
Google said one cryptocurrency wallet associated with one of the hacking groups received around $10 million in bitcoin in the first few months of this year. The company did not say exactly how that money was connected to individual victims or whether it represented ransom proceeds, but the figure suggests the operation may already be generating significant returns.
The researchers also said the hackers usually demand between $750,000 and $3 million from victims. Those demands place the campaign firmly in the high-stakes range typical of attacks aimed at large enterprises, especially firms with extensive confidential holdings and the resources to pay substantial sums under pressure.
The ransom range is also consistent with the type of target Google says is being pursued. Financial and investment firms may be seen as more likely to pay quickly if they fear disclosure of deal information, client records or other sensitive material.
Responses from named firms
Among the companies Reuters identified as potential victims, CME Group spokesperson Laurie Bischel declined to comment. Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s and TPG did not respond to requests for comment, according to the report.
Google did not say when the campaign began, how many organizations were compromised or whether any of the affected firms had paid. The company’s report instead focuses on the broader pattern: impersonation by phone, credential theft through spoofed sites, data theft and extortion through public leak threats.
A familiar threat with modern impact
The report is a reminder that cybercriminals do not always need highly sophisticated tooling to succeed. A phone call, a convincing impersonation and a fake login page can still create a path into some of the world’s most security-conscious organizations. When the target holds deal documents, strategic plans or private client files, the payoff for attackers can be substantial.
For financial firms in particular, the combination of vishing, credential theft and extortion creates a challenge that is both technical and organizational. Security teams have to defend identities, train employees to verify requests, and reduce the chance that a single mistaken approval opens the door to a broader breach.
Google’s report suggests that the threat is not isolated, not random and not limited to one industry. Instead, it appears to be a structured campaign aimed at high-value organizations where confidential information can be turned into leverage. Even as cybercriminals adopt newer tools, the company’s findings show that some of the most effective attacks still begin with a human voice on the phone.
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: August 7, 2026 at 6:38 pm
2 views
