Google Warns Hackers Are Calling Financial Firm Employees to Steal Data and Extort Victims

Google says hacking groups are using phone-based phishing attacks to target financial firms, steal sensitive data and extort victims by threatening to publish it.

Aug 9, 2026 - 07:05
 0
Google Warns Hackers Are Calling Financial Firm Employees to Steal Data and Extort Victims
Image Credit: Chatgpt

Hackers are targeting employees at major financial and investment firms with phone-based phishing attacks designed to steal credentials, access sensitive data and extort victims, according to Google security researchers.

Google said the groups are using an old-fashioned technique known as voice phishing, or vishing, in which attackers call employees on their personal phones while pretending to be co-workers or IT helpdesk staff. They then attempt to convince victims to enter their login credentials and multi-factor authentication codes into spoofed websites.

Google did not identify the companies targeted in its report. Reuters reported that victims include major private equity and financial firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG.

Hackers use stolen data for extortion

Google identified several groups involved in the attacks as Falcon, Helix, Pink and Redact. Some operate websites where they publicly claim responsibility for breaches and threaten to release stolen information unless victims pay.

One extortion site described data publication as a consequence of victims refusing to cooperate, while urging companies to respond quickly to negotiations.

Google said the groups could be connected through a broader threat actor it tracks as UNC6671. Researchers said it remains unclear whether the groups are affiliates, splinter operations or separate actors using the same phishing-as-a-service infrastructure.

“We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands,” Google researchers wrote, suggesting the structure could help attackers separate operations, conceal the overall scale of breaches and limit the fallout from individual negotiations.

Financial firms become a bigger target

The groups have previously targeted companies across manufacturing, real estate, healthcare, insurance, technology, transportation and hospitality. Their objectives have included stealing intellectual property, software source code and sensitive information belonging to high-value customers.

More recently, however, the attackers have focused on legal and financial organisations, including private equity firms. Google said targeting companies involved in mergers, acquisitions, capital deployment and litigation could give hackers access to particularly valuable corporate and confidential information.

That information can provide greater leverage when attackers demand payment to prevent its release.

The campaign also highlights how effective basic social engineering remains despite the growing use of AI-powered cyberattacks. Rather than exploiting sophisticated technical vulnerabilities, attackers can sometimes gain access simply by persuading an employee to trust a convincing phone call and hand over security credentials.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.