What happened
Google's threat intelligence group published new findings tying a cluster of voice-phishing crews, tracked as Falcon, Helix, Pink and Redact and possibly linked under a broader umbrella researchers call UNC6671, to a wave of extortion attacks against major financial firms. The groups call employees on their personal cellphones, posing as coworkers or internal IT support, and walk them through entering their login credentials and multi-factor authentication codes into convincing fake company login pages. Once inside, the attackers pull sensitive files and threaten to publish them on dedicated leak sites unless a ransom is paid. Confirmed or suspected targets named in the report include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG. Google says one cryptocurrency wallet tied to the campaign took in roughly $10 million in bitcoin in early 2026 alone, with individual ransom demands ranging from $750,000 to $3 million. Earlier waves from the same playbook hit manufacturing, healthcare, real estate, insurance, transportation and hospitality companies.
Why it matters for your business
Private equity firms and hedge funds are the current headline targets because a company mid-acquisition or mid-fundraise has the most reason to pay quietly and quickly, but the underlying trick works on any organization with a help desk. Vishing doesn't rely on a software bug, it relies on an employee wanting to be helpful to someone who sounds like a coworker or claims to be from IT. Local businesses with remote or hybrid staff, a shared IT inbox, or outsourced tech support are just as exposed, especially if employees are used to resetting their own passwords over the phone. A single successful call can hand an attacker the same access a stolen laptop would.
How to protect your team
Set a firm rule that IT support never asks for a password or MFA code over the phone, and that any login reset request gets verified through a separate, known channel before anyone acts on it. Give employees a documented way to confirm a caller's identity, such as calling back a listed internal extension rather than a number the caller provides. Review who at your company can approve access changes, and make sure that list is short and known. If in doubt, hang up and verify.
