Thursday, 6 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 6 August 2026 at 22:50

Google warns of hacking groups extorting financial firms via phone calls

Google's security researchers say unknown hacking groups are breaking into major US financial and investment firms using vishing, stealing data and demanding ransoms.

Foto: TechCrunch

In a report published on Thursday, Google's security researchers said that unidentified hacking groups are targeting large financial and investment firms in the United States, stealing sensitive data and threatening to make it public unless victims pay a ransom. Google did not name the victims, but Reuters reported that private equity firms and financial companies including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG are among them.

The groups, which Google calls Falcon, Helix, Pink, and Redact, rely on an old-fashioned technique: vishing, or voice phishing. They call employees on their personal cellphones, pretending to be coworkers or IT helpdesk staff, and try to trick them into entering their credentials and multi-factor authentication codes on spoofed websites.

Some of these groups operate extortion websites where they publicize their hacks and threaten to leak stolen data. One such site says that publication is never the preferred resolution, but rather a consequence of refusal to engage or deliberate stalling. Google researchers suggest the groups may all be part of a larger collective tracked as UNC6671, but it is unclear whether they are affiliates, splinter groups, or share the same phishing-as-a-service infrastructure. The report says this most likely reflects a coordinated group operating multiple public extortion brands to compartmentalize operations, hide overall breach volumes, and isolate negotiation fallout.

Earlier, the same groups targeted manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality companies, aiming to steal valuable intellectual property, software source code, or sensitive VIP client data. More recently, they have focused on legal and financial organizations, including private equity firms. Google notes that concentrating on companies involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate data to maximize leverage in extortion demands.

Regarding financial impact, Google said a cryptocurrency wallet associated with one of the groups received about $10 million in Bitcoin in the first few months of this year. Typical ransom demands range from $750,000 to $3 million. The named companies did not respond to requests for comment.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category