Cybercriminals Target Major U.S. Financial Firms in Vishing Extortion Campaign
Google’s security researchers revealed on Thursday that unidentified hacking groups are actively breaching large U.S. financial and investment firms to steal sensitive data and extort victims by threatening to leak it. Among the targeted organizations are prominent private equity firms, including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
The attackers tracked by Google under the names Falcon, Helix, Pink, and Redact employ voice phishing (vishing), a social engineering tactic where hackers impersonate coworkers or IT support over phone calls to trick employees into divulging credentials and multi-factor authentication codes on spoofed websites. Some groups operate dedicated leak sites to pressure victims into paying ransoms, with one site stating that data publication is a "consequence of refusal to engage."
Google’s report suggests these groups may operate under a larger collective, UNC6671, though their exact relationships whether affiliates, splinter factions, or users of a shared Phishing-as-a-Service infrastructure remain unclear. The researchers speculate the groups may compartmentalize operations to obscure breach volumes and isolate negotiation risks.
Beyond financial firms, the hackers have previously targeted manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors, seeking intellectual property, source code, and VIP client data. Their recent focus on legal and financial organizations particularly those involved in mergers, acquisitions, and litigation appears strategic, aiming to exploit high-value corporate data for maximum extortion leverage.
Financially, the groups have seen success: one cryptocurrency wallet linked to the operation received $10 million in Bitcoin in early 2024, with ransom demands typically ranging from $750,000 to $3 million per victim. Representatives for CME Group declined to comment, while the other named firms did not respond to inquiries.
Bain Capital TPRM report: https://www.rankiteo.com/company/bain-capital
Bridgewater Associates TPRM report: https://www.rankiteo.com/company/bridgewater-associates
Apollo Global Management TPRM report: https://www.rankiteo.com/company/apollo-global-management-llc
Blackstone TPRM report: https://www.rankiteo.com/company/blackstoneinc
KKR TPRM report: https://www.rankiteo.com/company/kkr
CME Group TPRM report: https://www.rankiteo.com/company/cme-group
Moody’s TPRM report: https://www.rankiteo.com/company/moodys-corporation
TPG TPRM report: https://www.rankiteo.com/company/tpg-capital
"id": "briapoblabaimoocmekkrtpg1786069583",
"linkid": "bridgewater-associates, apollo-global-management-llc, blackstoneinc, bain-capital, moodys-corporation, cme-group, kkr, tpg-capital",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'Apollo Global Management',
'type': 'Private Equity Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'Bain Capital',
'type': 'Private Equity Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'Blackstone',
'type': 'Private Equity Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'Bridgewater Associates',
'type': 'Investment Management Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'CME Group',
'type': 'Financial Services Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'KKR',
'type': 'Private Equity Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'Moody’s',
'type': 'Financial Services Firm'},
{'industry': 'Financial Services',
'location': 'U.S.',
'name': 'TPG',
'type': 'Private Equity Firm'}],
'attack_vector': 'Voice Phishing (Vishing)',
'data_breach': {'data_exfiltration': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Intellectual Property',
'Source Code',
'VIP Client Data',
'Corporate Data (M&A, '
'Litigation)']},
'date_publicly_disclosed': '2024-06-13',
'description': 'Unidentified hacking groups are actively breaching large U.S. '
'financial and investment firms to steal sensitive data and '
'extort victims by threatening to leak it. The attackers '
'employ voice phishing (vishing) to trick employees into '
'divulging credentials and multi-factor authentication codes. '
'Some groups operate dedicated leak sites to pressure victims '
'into paying ransoms.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'data leaks',
'data_compromised': ['Intellectual Property',
'Source Code',
'VIP Client Data',
'Corporate Data (M&A, Litigation)'],
'financial_loss': '$10 million in Bitcoin (early 2024)'},
'initial_access_broker': {'entry_point': 'Voice Phishing (Vishing)',
'high_value_targets': ['Legal and Financial '
'Organizations',
'Firms involved in M&A and '
'Litigation']},
'investigation_status': 'Ongoing',
'motivation': ['Financial Gain', 'Extortion', 'Data Theft'],
'post_incident_analysis': {'root_causes': ['Social Engineering (Vishing)',
'Credential Theft via Spoofed '
'Websites']},
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': ['$750,000', '$3 million']},
'references': [{'date_accessed': '2024-06-13',
'source': 'Google Security Research'}],
'threat_actor': ['Falcon', 'Helix', 'Pink', 'Redact', 'UNC6671'],
'title': 'Cybercriminals Target Major U.S. Financial Firms in Vishing '
'Extortion Campaign',
'type': ['Extortion', 'Data Breach', 'Vishing'],
'vulnerability_exploited': 'Social Engineering (Impersonation of coworkers/IT '
'support)'}