

Google has warned that hackers are calling employees at major US financial firms to steal private company data. The attackers pretend to be IT workers and ask employees to share login credentials and MFA codes. Hackers then use the stolen information to enter company systems and demand money.
The attacks target financial and investment firms across the US, with Blackstone, Apollo Global Management, KKR, TPG, CME Group, Moody’s and Bain Capital among reported victims. Google identified four groups called Falcon, Helix, Pink and Redact behind the attacks.
Hackers often call employees on personal phones and create a sense of urgency. They may claim that an employee needs to update a passkey or fix an MFA problem. The caller then sends a link to a fake company login page.
The fake website collects passwords and MFA codes during the call. Hackers can quickly use those details to enter cloud accounts and steal sensitive business information.
Google believes the four groups may be connected to a wider operation called UNC6671. Researchers found similar methods and websites associated with different hacking brands.
Google researchers said, “We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands.”
The quote appears in Google Threat Intelligence’s official report. Hackers have also targeted companies in healthcare, technology, insurance, manufacturing and other sectors. Financial firms now face greater risk since they hold valuable client and business information.
Google said one Bitcoin wallet linked to the hackers received about $10 million during the first months of 2026. The groups can demand millions from companies after stealing sensitive data.
Google recommends stronger MFA, passkeys, and better monitoring of company accounts. Employees should also verify unexpected IT calls through official company channels before sharing any login information.
Also Read: Google Maps Brings Gemini-Powered Ask Maps Feature to India