News

Hackers Target Blackstone, KKR, CME with Fake IT Support Calls

Blackstone, KKR, CME Group among major US financial firms targeted by hackers using fake IT support calls, phishing websites and stolen authentication credentials to access systems.

Written By : Humpy Adepu

Several major US financial firms, including Blackstone, KKR, Apollo Global Management, Bridgewater Associates, Bain Capital, TPG and CME Group, have been targeted by hackers using fake IT support calls and fraudulent websites to steal employee passwords and authentication codes.

The campaign was identified through data from Google and internet intelligence reviewed by Reuters. Google’s Threat Intelligence Group (GTIG) is tracking the activity as UNC6671, a threat actor linked to extortion brands including Redact, Pink, Helix and Falcon.

Google said the group continues to compromise organizations to steal data and demand extortion payments, despite the reported shutdown of its earlier BlackFile operation

Hackers Posed as IT Support Staff

The attackers used voice phishing, or vishing, to contact employees while posing as company IT helpdesk staff. The calls created urgency around security-related tasks, including updating authentication methods or enabling passkeys.

Employees were then directed to websites designed to resemble legitimate company login and authentication pages. These sites were used to collect passwords, login details and other authentication credentials.

Google said the attackers could also use adversary-in-the-middle techniques to intercept authentication sessions and MFA tokens.

Blackstone, KKR Among Firms Targeted

The companies identified in the campaign include Blackstone, Apollo Global Management, Bridgewater Associates, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.

Other businesses and professional services firms were also targeted. However, being targeted does not necessarily mean that a company was successfully breached. The data shows that attackers created infrastructure and attempted to compromise organizations, while the outcome of individual attempts varied.

Google’s analysis found that UNC6671’s focus changed during 2026. Earlier activity involved manufacturing, real estate, healthcare and insurance. By July, the group had increasingly targeted financial and legal organizations, including private equity firms, law firms and financial ratings agencies.

Also Read: Google and Blackstone Launch $5B AI Cloud Venture to Expand TPU Access

Stolen Credentials Could Lead To Data Theft

After obtaining credentials, attackers can attempt to access corporate cloud services, including Microsoft 365 and Okta. The broader objective is to steal data and extort victims.

Google’s analysis of cryptocurrency wallets linked to the earlier BlackFile operation found that 18 Bitcoin addresses received a combined 141.65 BTC, worth approximately $10.69 million at the time of the transactions.

Initial ransom demands typically ranged from around $1 million to more than $3 million, although negotiations often resulted in lower payments.

The campaign highlights the risks posed by social engineering, where attackers use convincing phone calls and fake login pages to bypass security measures by targeting employees directly.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Crypto News Today: Jimothy Raccoon Meme Coin Jumps 331% After Elon Musk’s Post

Crypto News Today: Trump Media Scraps Crypto.com CRO Plans

Crypto News Today: Institutional OTC Trading Reshapes Crypto Market Cycles in 2026

7 Altcoins Investors Are Watching This Month

EU Crypto Scams Rise as MiCA Transition Sparks Fraud