Key Takeaways
- Despite advances in AI‑driven cyber threats, traditional voice phishing (vishing) remains highly effective against large firms.
- Google’s Threat Analysis Group identified four hacking clusters—Falcon, Helix, Pink, and Redact—targeting U.S. private‑equity and investment companies to steal data for extortion.
- The attackers impersonate coworkers or IT help‑desk staff via phone calls, guiding victims to spoofed login pages where credentials and multi‑factor codes are harvested.
- Stolen information is leveraged on extortion sites that threaten public disclosure unless a ransom (typically $750 k–$3 million) is paid; one associated crypto wallet has already received roughly $10 million in Bitcoin.
- Google suspects the groups may operate under a larger umbrella tracked as UNC6671, possibly sharing infrastructure or affiliations while maintaining separate public extortion brands.
- Earlier campaigns hit manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors; the recent shift to legal and financial firms aims to capture high‑value merger, acquisition, litigation, and VIP client data.
- Victims named in reports include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG, though most have declined to comment.
Overview of the Threat Landscape
Even as attackers adopt sophisticated AI‑powered tools, low‑tech social engineering continues to yield significant returns. Google’s security researchers observed that a series of voice‑phishing campaigns—commonly known as vishing—are successfully compromising major financial and investment institutions in the United States. The technique relies on deception rather than zero‑day exploits, proving that human factors remain the weakest link in corporate defenses.
Identity of the Attacking Groups
Google’s Threat Analysis Group labelled the perpetrators Falcon, Helix, Pink, and Redact. These clusters appear to be part of a broader activity set the company tracks under the designation UNC6671. While it is uncertain whether they are formal affiliates, splinter factions, or merely users of a shared Phishing‑as‑a‑Service platform, their coordinated tactics suggest a level of organization beyond lone actors.
Primary Attack Vector: Voice Phishing
The core method involves placing telephone calls to employees’ personal cellphones. Posing as trusted coworkers or IT help‑desk personnel, the callers convince targets to visit fraudulent websites that mimic legitimate corporate portals. Once on the spoofed site, victims are prompted to enter usernames, passwords, and multi‑factor authentication codes, which the attackers then harvest for illicit access.
Extortion Tactics and Public Leak Threats
After gaining entry, the hackers exfiltrate sensitive data and subsequently publish portions of it on dedicated extortion sites. These platforms feature messages such as: “We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement.” The implied promise is that prompt, good‑faith payment will prevent further disclosure, while non‑compliance risks public exposure of confidential information.
Financial Motivation and Cryptocurrency Payments
Monetary gain drives the campaign. Google reported that a Bitcoin wallet linked to one of the groups received approximately $10 million in the first months of the year. Ransom demands typically range from $750,000 to $3 million per victim, reflecting the perceived value of the stolen intellectual property, source code, or VIP client data.
Historical Targeting and Recent Shift
Before focusing on private‑equity firms, the same actors had infiltrated companies across manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality sectors. The recent pivot toward legal and financial organizations aligns with a strategy to capture high‑value information related to mergers, acquisitions, capital deployment, and litigation—data that can amplify extortion leverage.
Victim Profile and Corporate Response
Among the named victims are Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. Representatives from CME Group declined to comment, while the other firms either did not respond to requests for comment or offered no public statement. This silence underscores the sensitivity of the incidents and the potential reputational risk associated with acknowledging a breach.
Attribution and Organisational Structure
Google analysts hypothesize that Falcon, Helix, Pink, and Redact may constitute a coordinated threat‑actor collective operating multiple public extortion brands. Such fragmentation could serve to compartmentalize operations, obscure the true scale of breaches, and isolate fallout from individual negotiations, thereby reducing the likelihood of law‑enforcement attribution.
Conclusion: Enduring Relevance of Social Engineering
The campaign highlighted in Google’s report reinforces a critical lesson for enterprises: advanced technological defenses alone cannot eliminate risk when attackers exploit human psychology. Regular employee training, robust verification procedures for unsolicited requests, and multi‑layered authentication mechanisms remain essential to counter persistent vishing threats, even in an era dominated by AI‑driven malware.

