Several major US financial firms, including Blackstone, KKR, Apollo Global Management, Bridgewater Associates, Bain Capital, TPG and CME Group, have been targeted by hackers using fake IT support calls and fraudulent websites to steal employee passwords and authentication codes.
The campaign was identified through data from Google and internet intelligence reviewed by Reuters. Google’s Threat Intelligence Group (GTIG) is tracking the activity as UNC6671, a threat actor linked to extortion brands including Redact, Pink, Helix and Falcon.
Google said the group continues to compromise organizations to steal data and demand extortion payments, despite the reported shutdown of its earlier BlackFile operation
The attackers used voice phishing, or vishing, to contact employees while posing as company IT helpdesk staff. The calls created urgency around security-related tasks, including updating authentication methods or enabling passkeys.
Employees were then directed to websites designed to resemble legitimate company login and authentication pages. These sites were used to collect passwords, login details and other authentication credentials.
Google said the attackers could also use adversary-in-the-middle techniques to intercept authentication sessions and MFA tokens.
The companies identified in the campaign include Blackstone, Apollo Global Management, Bridgewater Associates, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.
Other businesses and professional services firms were also targeted. However, being targeted does not necessarily mean that a company was successfully breached. The data shows that attackers created infrastructure and attempted to compromise organizations, while the outcome of individual attempts varied.
Google’s analysis found that UNC6671’s focus changed during 2026. Earlier activity involved manufacturing, real estate, healthcare and insurance. By July, the group had increasingly targeted financial and legal organizations, including private equity firms, law firms and financial ratings agencies.
Also Read: Google and Blackstone Launch $5B AI Cloud Venture to Expand TPU Access
After obtaining credentials, attackers can attempt to access corporate cloud services, including Microsoft 365 and Okta. The broader objective is to steal data and extort victims.
Google’s analysis of cryptocurrency wallets linked to the earlier BlackFile operation found that 18 Bitcoin addresses received a combined 141.65 BTC, worth approximately $10.69 million at the time of the transactions.
Initial ransom demands typically ranged from around $1 million to more than $3 million, although negotiations often resulted in lower payments.
The campaign highlights the risks posed by social engineering, where attackers use convincing phone calls and fake login pages to bypass security measures by targeting employees directly.