Google says hackers are calling financial firm employees to hack and extort victims
Google's security researchers have identified groups of hackers targeting financial and investment firms in the US, using phone calls to trick employees into entering their credentials and extorting them with the threat of publishing stolen data.
Intelligence analysis by Llama

Google's security researchers have identified groups of hackers targeting financial and investment firms in the US, using phone calls to trick employees into entering their credentials and extorting them with the threat of publishing stolen data. The hackers, who Google has dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique known as voice phishing, or vishing…
Imagine you get a call from someone who claims to be your coworker. They ask you to enter your password and some special codes on a fake website. This is called voice phishing, and it's a way for hackers to trick people into giving them their secrets. The hackers then use this information to steal money or important data from the company.
Analysis
Hacking Groups Target Financial Firms in the US
Google's security researchers have identified groups of hackers targeting financial and investment firms in the US, using phone calls to trick employees into entering their credentials and extorting them with the threat of publishing stolen data. The hackers, who Google has dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique known as voice phishing, or vishing, to break into the firms.
According to Google, the hacking groups have previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies. They have also targeted legal and financial organizations such as private equity firms. The hackers usually demand from $750,000 to $3 million from victims, and have received around $10 million in bitcoin in the first few months of this year.
Google's researchers believe that the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671. However, it's unclear if they are affiliates, splinter groups, or they all use the same Phishing-as-a-Service infrastructure.
The hacking groups have also targeted private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG. These firms did not respond to a request for comment.
The Threat of Voice Phishing
Voice phishing, or vishing, is a technique used by hackers to trick victims into doing things they shouldn't. The hackers call the victims' personal cellphones and pretend to be co-workers or IT helpdesk staffers, during which they try to trick targets into entering their credentials and multi-factor codes on spoofed websites.
According to Google, the hacking groups have also previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies. They have also targeted legal and financial organizations such as private equity firms.
The Impact of the Hacking Groups
The hacking groups have had a significant impact on the financial and investment firms they have targeted. The hackers have stolen sensitive data, including valuable intellectual property, software source code, and sensitive VIP client data. They have also extorted the victims with the threat of publishing the stolen data.
Google's researchers believe that the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671. However, it's unclear if they are affiliates, splinter groups, or they all use the same Phishing-as-a-Service infrastructure.
Conclusion
The hacking groups identified by Google pose a significant threat to financial and investment firms in the US. The use of voice phishing and other techniques to trick employees into entering their credentials and extorting them with the threat of publishing stolen data is a serious concern. Financial and investment firms must take steps to protect themselves against these types of attacks.
Key points
- Google's security researchers have identified groups of hackers targeting financial and investment firms in the US, using phone calls to trick employees into entering their credentials and extorting them with the threat of publishing stolen data.
- The hackers, who Google has dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique known as voice phishing, or vishing, to break into the firms.
- The hacking groups have previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies.
- The hackers usually demand from $750,000 to $3 million from victims, and have received around $10 million in bitcoin in the first few months of this year.
- Google's researchers believe that the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671.
If the financial and investment firms take steps to protect themselves against these types of attacks, they may be able to prevent the hackers from stealing sensitive data and extorting them with the threat of publishing the stolen data. This could lead to a reduction in the number of successful hacking attacks and a decrease in the financial losses suffered by the firms.
If the financial and investment firms do not take steps to protect themselves against these types of attacks, the hackers may continue to steal sensitive data and extort them with the threat of publishing the stolen data. This could lead to a significant increase in the number of successful hacking attacks and a substantial increase in the financial losses suffered by the firms.


