Thursday, August 27, 2026
Tech Beat
Aug 6, 2026, 7:40 PMCybersecurity

Google Warns UNC6671 Linked Hackers Are Vishing Major Financial Firms

Google says UNC6671 linked hackers use phone phishing to breach major US financial firms and demand ransoms of $750,000 to $3 million per victim.

A telephone receiver forms a fishhook pulling a key and bitcoin from a cracked financial vault.

Summary

On August 6, 2026, Google said unknown hackers were calling employees’ personal cellphones while posing as co-workers or IT helpdesk staff, then directing them to spoofed websites that capture credentials and multi-factor codes. The vishing campaign targets large US financial, investment and legal organizations, stealing sensitive data for leak threats and ransom demands of $750,000 to $3 million. Google withheld victim names, but Reuters identified Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG. CME spokesperson Laurie Bischel declined comment, while the others did not respond.

Google named the groups Falcon, Helix, Pink and Redact, saying they may be coordinated brands within UNC6671, although they could instead be affiliates, splinter groups or users of shared Phishing-as-a-Service infrastructure. Some operate public leak sites, and one says data publication follows refusal to negotiate, stalling or broken agreements. Google believes multiple brands could compartmentalize operations, conceal total breach volumes and contain negotiation fallout. One associated cryptocurrency wallet received about $10 million in bitcoin during the first months of 2026. Earlier targets spanned manufacturing, real estate, healthcare, insurance, technology, transportation and hospitality, with attackers seeking intellectual property, source code and sensitive VIP client data. The newer focus on private equity, mergers, acquisitions, capital deployment and litigation offers high-value confidential information that can increase extortion leverage.

Positives

  • Google identified Falcon, Helix, Pink and Redact, plus a possible UNC6671 umbrella, giving defenders concrete labels for tracking the campaign.
  • Researchers documented personal-cellphone vishing, spoofed credential pages and multi-factor code theft, clarifying the attackers’ access method.
  • Google traced about $10 million in early 2026 bitcoin receipts to one associated wallet, providing investigators with a financial lead.

Risks & concerns

  • Reuters identified Apollo, Bain Capital, Blackstone, Bridgewater, CME Group, KKR, Moody’s and TPG among the reported targets.
  • Hackers typically demand $750,000 to $3 million and threaten to publish stolen data when victims refuse or delay payment.
  • The campaign has pursued intellectual property, source code and sensitive VIP client data across financial organizations and seven other major sectors.
  • Google cannot yet determine whether Falcon, Helix, Pink and Redact are affiliates, splinter groups or customers of shared phishing infrastructure.
Primary sourceTechCrunchhttps://techcrunch.com/2026/08/06/google-says-hackers-are-calling-financial-firm-employees-to-hack-and-extort-victims/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing

CybersecurityAug 26

FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate