
Phone-scam hackers now target Wall Street's biggest firms
Google Threat Intelligence Group (GTIG) detailed an extortion group it tracks as UNC6671, whose targeting shifted in July from a broad mix of industries to private equity firms, hedge funds, major law firms, and financial rating agencies. The attack relies on vishing — voice phishing — with attackers calling employees on their personal mobile phones, posing as IT helpdesk staff urgently requiring a passkey or MFA setup.
The call directs victims to a spoofed login portal, where adversary-in-the-middle infrastructure intercepts credentials and multi-factor authentication tokens mid-"setup." Once inside, the attackers run automated scripts to pull data from cloud services like Microsoft 365 and Okta, while deleting password-reset and security-setting-change notifications to stay under the radar. Google published 72 domains used in the campaign but withheld the specific victims — though Reuters worked them out by feeding the addresses into tools like DomainTools and urlscan, which surfaced subdomains tied to specific companies: Blackstone, KKR, Apollo Global Management, CME Group, law firms Paul Hastings and Greenberg Traurig, and investment firms Point72, Citadel, Millennium Management, and Two Sigma.
- UNC6671 shifted to private equity firms, hedge funds, and law firms in July
- The attack runs through calls to employees' personal phones, posing as IT helpdesk staff
- None of the companies named by Reuters has confirmed a breach
The named companies' response has been measured so far: Greenberg Traurig told Reuters no breach occurred, Point72 told investors it saw "no early sign that client information was taken," and Two Sigma confirmed its security team "responded quickly to an attempted vishing campaign," with no impact to systems or data. GTIG assesses the group operates under several extortion brands — BlackFile, Redact, Pink, Helix, and Falcon — on shared infrastructure, with typical ransom demands of $1-3 million, though most cases settle around $750,000. We've seen a similar shift toward larger, more organized targets in social engineering within crypto too — a fourth wave of attacks on Coldcard hardware wallet users pushed combined losses toward $114 million.
None of this should be read as personalized investment advice.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7

Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
226AI




