Even in an era of AI-powered autonomous cyberattacks, the old-fashioned art of tricking people over the phone is still paying off handsomely. Google’s security researchers reported Thursday that unknown hacking groups are systematically targeting large US financial and investment firms, using voice phishing—or “vishing”—to steal sensitive data and extort victims with threats of public leaks. The attacks have already netted the perpetrators millions in Bitcoin, according to the report.
Google did not name the victims, but Reuters reported that among the targets are leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. None of these firms responded to requests for comment.
Also read: Ex-Spotify engineers raise $10M to bring real-time AI personalization to e-commerce
How the vishing attacks work
Google’s researchers, who dubbed the hacking groups Falcon, Helix, Pink, and Redact, described a deceptively simple technique: hackers call employees on their personal cellphones, pretending to be coworkers or IT helpdesk staff. During these calls, they attempt to trick targets into entering their credentials and multi-factor authentication codes on spoofed websites.
This approach bypasses many traditional security measures, because it exploits human trust rather than technical vulnerabilities. “Even with advanced security tools, a well-crafted phone call can be the weakest link,” the report notes.
Also read: Tesla hits 10 million EVs built, but the hardest part of Musk's pay package lies ahead
Some of the groups operate public-facing websites where they advertise their hacks and threaten to leak stolen data as tap into for ransom payments. One such site read: “We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement. Respond promptly and in good faith, and the matter is resolved without further incident.”
Coordinated extortion operation
Google’s researchers believe the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671. It remains unclear whether they are affiliates, splinter groups, or simply share the same Phishing-as-a-Service infrastructure.
“We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” the report stated.
The financial scale of the operation is significant. Google said one cryptocurrency wallet associated with the hacking groups received around $10 million in Bitcoin in the first few months of this year alone. The hackers typically demand ransoms ranging from $750,000 to $3 million per victim.
Why financial firms are prime targets
While the groups have previously targeted manufacturing, real estate, healthcare, and insurance companies, their recent focus on legal and financial organizations—particularly private equity firms—appears deliberate. Google’s researchers noted that “concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize use extortion demands.”
For private equity and investment firms, the stakes are especially high. A data breach involving pending merger terms, investor identities, or litigation strategy could cause irreparable reputational damage and financial loss, making these firms more likely to pay.
The attacks highlight a growing trend: even as cybersecurity defenses improve, social engineering remains one of the most effective attack vectors. Employees are often the last line of defense, and a convincing phone call can undo months of security training.
For firms in the financial sector, the takeaway is clear: verify identities through independent channels, never enter credentials on a website reached via a phone call, and treat unsolicited requests for multi-factor codes with extreme suspicion. The cost of a single successful vishing call can run into millions—both in ransom payments and in lost trust.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. The cryptocurrency market is highly volatile and uncertain; readers should conduct their own research before making any investment decisions.