Hackers Are Calling Financial Firm Employees to Steal Data and Demand Ransom

Google's security researchers reported on August 6, 2026, that groups of unknown hackers are targeting and breaking into large U.S. financial and investment firms to steal sensitive data and extort victims with threats of publishing it (TechCrunch). Reuters reported that among the targeted firms are Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG (Reuters).
Google tracks the different hacking groups under the umbrella name UNC6671, though it is unclear if they are affiliates, splinter groups, or share the same phishing toolkits. Google has dubbed the individual groups Falcon, Helix, Pink, and Redact. Google believes the groups most likely reflect a coordinated set of attackers operating multiple public extortion brands, possibly to separate their operations, hide the total number of breaches, and keep fallout from failed negotiations contained.
The hacking groups used a technique called voice phishing, or "vishing." In simple terms, they called employees on their personal cellphones pretending to be coworkers or IT support staff. The goal was to trick employees into typing their usernames, passwords, and security codes into fake websites that looked like the real thing. Some of the hacking groups also run websites where they publicly showcase stolen data and threaten to leak it unless the victim pays a ransom.
Google said the hackers usually demand between $750,000 and an unspecified higher amount as ransom. A Bitcoin wallet tied to one of the hacking groups received around $10 million in the first few months of 2026.
The hacking groups previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies. In those earlier attacks, they sought valuable intellectual property, software source code, or sensitive VIP client data. Google said the recent shift toward legal and financial organizations may reflect a strategy to target the most valuable confidential data, giving the hackers more leverage when demanding a ransom.
Google's threat-intelligence report 'The Cost of a Call: From Voice Phishing to Data Extortion' describes extortion that involves calls or emails to employees of the victim organization demanding payment in bitcoin within 72 hours. Google Threat Intelligence Group's report 'Welcome to BlackFile: Inside a Vishing Extortion Operation' documents an expansive vishing extortion campaign by the threat actor UNC6671 operating under the BlackFile brand.
Google's report 'Ongoing Targeted Campaign Against US Law Firms' states the threat cluster delivers unbranded extortion communications via email shortly after successfully stealing data, often within 30 minutes of the theft. Google's report 'Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft' states that ShinyHunters-branded operations use vishing and victim-branded websites to steal data from cloud-based applications. Google's threat-intelligence reporting also characterizes financially motivated actors as carrying out extortion against the defense industrial base and the broader manufacturing base.
On June 5, 2026, Google and the FBI warned about a ransomware gang known as Silent Ransom Group that sends people pretending to be IT support employees to law firms' offices to hack victims in person.
The broader context here is the sheer speed of these attacks. When attackers can go from a phone call to stealing data to demanding a ransom within 30 minutes, security teams have almost no time to detect the breach and stop it before the pressure is applied.
The use of multiple brand names also raises a concern. By operating under several public extortion brands like BlackFile and ShinyHunters while coordinating behind the scenes under the UNC6671 umbrella, the attackers appear to be treating their extortion operations like a portfolio of products. If one brand attracts too much attention or a negotiation falls through, the others can keep running without interruption.
These attacks also reveal a persistent weakness in how companies protect themselves. Security codes sent to phones are meant to add a second layer of protection, but the hackers get around this by creating fake login pages that capture both the password and the temporary code in real time, then use them immediately on the real site. The shift toward financial and legal targets, after earlier campaigns against manufacturing and healthcare, suggests these attackers are looking for data that gives them the most leverage per break-in.
The $10 million in Bitcoin received by a single group's wallet in early 2026, combined with ransom demands starting at $750,000, suggests the economics of this campaign are currently working in the attackers' favor. The reliance on phone calls and in-person deception rather than advanced technical exploits indicates that human trust, not software flaws, remains the most reliable way in for high-value targets.


