Cybercriminals are increasingly employing voice phishing, or ‘vishing,’ to infiltrate major financial and investment firms in the United States. This method involves calling employees on their personal phones, impersonating colleagues or IT support staff, and persuading them to divulge login credentials and multi-factor authentication codes on counterfeit websites.
Google’s security researchers have identified several hacking groups—dubbed Falcon, Helix, Pink, and Redact—engaging in these tactics. These groups often operate websites where they publicize their breaches and threaten to release stolen data unless a ransom is paid. The ransom demands typically range from $750,000 to $3 million, with one associated cryptocurrency wallet receiving approximately $10 million in Bitcoin in the early months of this year.
While Google did not disclose specific victims, reports indicate that prominent private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG have been targeted. These organizations are attractive to cybercriminals due to their involvement in mergers, acquisitions, and capital deployment, which often involve sensitive and valuable data.
These hacking groups may be part of a larger collective tracked by Google as UNC6671. The exact relationships among these groups—whether they are affiliates, splinter factions, or users of the same Phishing-as-a-Service infrastructure—remain unclear. However, their coordinated efforts suggest a strategic approach to compartmentalize operations and maximize extortion leverage.
In addition to financial firms, these cybercriminals have previously targeted sectors such as manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality. Their primary objective is to steal valuable intellectual property, software source code, or sensitive client data to enhance their extortion demands.
The resurgence of vishing underscores the persistent effectiveness of social engineering tactics in cyberattacks. Organizations must bolster their security protocols by implementing comprehensive employee training programs, enhancing multi-factor authentication processes, and fostering a culture of vigilance to mitigate the risks associated with such deceptive practices.