Google warns of hacking calls aimed at financial firm employees
Google says callers posing as IT staff targeted financial firms to capture passwords and MFA codes, then threaten data leaks for ransom.
By Jordan Bell · Startups & Deals Reporter
· 3 min read
Google financial firm hacking calls are the focus of a new warning from the company’s threat-intelligence team: attackers have been phoning employees at financial-services organizations, posing as internal IT staff and trying to take over accounts. For investors, the episode is a reminder that a company’s security exposure can stem from an employee being persuaded to hand over a live login code, rather than from a newly discovered software flaw.
Google said the campaign recently focused on private-equity firms, law firms and financial-ratings agencies. The attackers’ apparent aim was to obtain sensitive data and then demand payment under threat of publishing it, according to reporting by TechCrunch and Reuters.
Google refers to public-facing extortion brands used in the activity as Falcon, Helix, Pink and Redact. Its researchers assess that the operations may be connected to a broader cluster it calls UNC6671. Google said the exact relationship is unresolved: the brands could be affiliates, splinter groups or separate users of the same phishing infrastructure.
How do the Google financial firm hacking calls work?
The approach is voice phishing, often shortened to “vishing.” According to Google’s account, a caller reaches an employee’s personal phone while claiming to be from the company help desk or another internal team. The caller directs the target to a look-alike website and seeks their password and multifactor-authentication code.
Multifactor authentication, or MFA, normally requires a second proof of identity after a password, such as a temporary code from an app or text message. It can still fail in this situation if a person is convinced to enter or read out that temporary code while the attacker is attempting to log in. The reported campaign relied on that social-engineering tactic, not a claimed technical exploit.
Reuters reported that it examined 72 malicious websites and found company-specific lures apparently associated with Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody’s, among others. That evidence indicates attempted targeting, not confirmed breaches. Google did not publicly identify victims, and a Google threat analyst told Reuters that the subdomains were likely used in attempted intrusions but that not all attempts succeeded.
What is known about the extortion claims?
Some of the groups run websites that advertise alleged intrusions and threaten data releases, TechCrunch reported. Google said some unnamed companies paid ransoms, according to Reuters, but Reuters could not determine which organizations were successfully compromised.
The warning is separate from Google’s June 2025 reporting on UNC6040, another financially motivated group that used fake IT-support calls to obtain access to organizations’ Salesforce environments. In that earlier case, Google said attackers manipulated users into approving a malicious connected application or giving up credentials and MFA codes, rather than exploiting a vulnerability in Salesforce itself.
The common thread is that a security control only works when the person using it can verify who is asking. Google’s latest reporting does not establish that every financial firm linked to a tailored phishing page was breached, but it shows how phone-based impersonation can bypass defenses when an employee is pressured to act in real time.
This story draws on original reporting from TechCrunch.