Technology

Google Identifies Coordinated Vishing and Extortion Campaign Against Major U.S. Financial Firms

Martin HollowayPublished 2d ago4 min readBased on 9 sources
Reading level
Google Identifies Coordinated Vishing and Extortion Campaign Against Major U.S. Financial Firms
Photo by Google / Public domain

Google's security researchers reported on August 6, 2026, that groups of unknown hackers are targeting and breaking into large U.S. financial and investment firms to steal sensitive data and extort victims with threats of publishing it TechCrunch. Reuters reported that among the targeted firms are Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG Reuters.

Google tracks the different hacking groups under the umbrella collective name UNC6671, though it is unclear if they are affiliates, splinter groups, or share the same Phishing-as-a-Service infrastructure. Google has dubbed the individual groups Falcon, Helix, Pink, and Redact. Google believes the groups most likely reflect a coordinated set of threat actors operating multiple public extortion brands, possibly to compartmentalize operations, hide overall breach volumes, and isolate negotiation fallout.

The hacking groups used voice phishing (vishing): phone calls to employees' personal cellphones in which hackers posed as coworkers or IT helpdesk staff to trick targets into entering credentials and multi-factor codes on spoofed websites. Some of the hacking groups run websites publicizing their hacks and threatening to leak stolen data to extort victims into paying a ransom.

Google said the hackers usually demand between $750,000 and an unspecified higher amount as ransom. A cryptocurrency wallet associated with one of the hacking groups received around $10 million in Bitcoin in the first few months of 2026.

The hacking groups previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies, seeking valuable intellectual property, software source code, or sensitive VIP client data. Google said the recent targeting of legal and financial organizations may reflect a strategy to target high-value corporate and confidential data to maximize leverage in extortion demands.

Google's threat-intelligence report 'The Cost of a Call: From Voice Phishing to Data Extortion' describes extortion that involves calls or emails to employees of the victim organization demanding payment in bitcoin within 72 hours. Google Threat Intelligence Group's report 'Welcome to BlackFile: Inside a Vishing Extortion Operation' documents an expansive vishing extortion campaign by the threat actor UNC6671 operating under the BlackFile brand.

Google's report 'Ongoing Targeted Campaign Against US Law Firms' states the threat cluster delivers unbranded extortion communications via email shortly after successfully stealing data, often within 30 minutes of the theft. Google's report 'Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft' states that ShinyHunters-branded operations use vishing and victim-branded websites to steal data from cloud-based SaaS applications. Google's threat-intelligence reporting also characterizes financially motivated actors as carrying out extortion against the defense industrial base and the broader manufacturing base.

On June 5, 2026, Google and the FBI warned about a ransomware gang known as Silent Ransom Group that sends people pretending to be IT support employees to law firms' offices to hack victims in person.

The operational tempo here is notable. The shift from pure credential theft to immediate, coercive extortion tightens the incident-response window dramatically. When attackers can pivot from initial vishing contact to data exfiltration and a ransom demand within 30 minutes, security teams have almost no room for detection and containment before the leverage is applied.

The branding strategy also warrants attention. By operating under multiple public extortion brands like BlackFile and ShinyHunters while coordinating under the UNC6671 umbrella, the actors appear to be treating their extortion operations as a portfolio. Compartmentalization limits reputational damage to any single brand if a particular negotiation collapses or draws law enforcement scrutiny, allowing the underlying infrastructure to persist.

The intersection of social engineering and SaaS data theft also highlights a persistent gap in enterprise defenses. MFA bypass via real-time adversary-in-the-middle techniques against spoofed login pages remains highly effective against employees trained to respond to caller-ID spoofing and authoritative-sounding IT staff. The move to target financial and legal sectors specifically, following earlier campaigns against manufacturing and healthcare, suggests these actors are optimizing for data that carries the highest extortion value per successful breach.

The $10 million in Bitcoin received by a single group's wallet in early 2026, combined with ransom demands starting at $750,000, suggests the economics of this campaign are currently working in the attackers' favor. The use of vishing and physical infiltration rather than zero-day exploits or novel malware indicates that human trust, not technical vulnerability, remains the most reliable access vector for high-value targets.