Even in the age of AI-powered autonomous cyberattacks, the crude, tried and tested hacking techniques of tricking victims into doing things they shouldn’t are still producing great results. Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort
Even in the age of AI-powered autonomous cyberattacks, the crude, tried and tested hacking techniques of tricking victims into doing things they shouldn’t are still producing great results.
Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims with the threat of publishing it, Google’s security researchers wrote in a report on Thursday.
The company did not name the victims, but Reuters reported that among them there are leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
The hacking groups, which Google dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique to break into those firms: phone calls to employees’ personal cellphones in which the hackers pretend to be co-workers or IT helpdesk staffers, during which they try to trick targets into entering their credentials and multi-factor codes on spoofed websites, according to Google. In cybersecurity parlance, this technique is known as voice phishing, or vishing.
Some of the groups identified by Google run websites where they publicize their hacks and threaten to leak the stolen data as a way to extort the victims into paying a ransom, a common strategy among cybercriminals.

“We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” read one of the sites. “Respond promptly and in good faith, and the matter is resolved without further incident.”
Google researchers said that the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671. But it’s unclear if they are affiliates, splinter groups, or they all use the same Phishing-as-a-Service infrastructure.
“We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” read the report.
According to Google, the hacking groups have also previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies with the goal of stealing “valuable intellectual property, software source code, or sensitive VIP client data.”
More recently, the hackers have targeted legal and financial organizations such as private equity firms. “Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands,” wrote Google’s researchers.
Google said that one cryptocurrency wallet associated with one of the hacking groups received around $10 million in bitcoin in the first few months of this year, and that the hackers usually demand from $750,000 to $3 million from victims.
Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG did not respond to a request for comment.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
For more tech updates, stay tuned to our blog.














