Google Warns Hackers Are Calling Wall Street Employees in Multimillion-Dollar Extortion Campaign

· · Views: 2,145 · 3 min time to read

Hackers are targeting employees at major US financial and investment firms with a surprisingly familiar weapon: the telephone. Instead of relying only on sophisticated malware, the attackers are impersonating corporate IT staff, manipulating employees into surrendering passwords and security codes, and then using stolen data to demand multimillion-dollar payments.

Hackers Call Employees on Personal Phones

The campaign depends heavily on voice phishing, or “vishing,” which attempts to convince employees that the person calling them is someone they should trust.

TechCrunch said attackers contact workers on their personal cellphones while pretending to be colleagues or IT help-desk employees, then direct them toward spoofed websites where passwords and multifactor authentication codes can be captured.

NDTV shared that the hackers use meticulous social engineering tactics, sometimes making the legitimate company help-desk number appear on the employee’s phone. Attackers claim an urgent IT directive requires the employee to update a passkey or multifactor authentication and send the victim to sites using names such as “passkeyhelpdesk” or “secure-passkey.”

If the victim enters a password, the attackers attempt to collect the security code generated by text message or authentication app while the phone conversation is still underway.

Blackstone, Apollo and Other Financial Giants Targeted

Google did not publicly identify the affected companies, but researchers and journalists connected malicious infrastructure with some of Wall Street’s largest institutions.

Reuters identified Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG among organizations targeted by attacker-controlled websites.

Investigators analyzed 72 malicious websites disclosed by Google using DomainTools and urlscan, uncovering company-specific subdomains apparently designed for attempted intrusions. Google threat analyst Austin Larsen cautioned that the sites were not necessarily successful in every case.

NDTV reported that KKR, Bain Capital, CME Group, TPG and Apollo declined to comment, while Blackstone, Bridgewater Associates and Moody’s did not immediately respond.

Ransom Demands Reach $3 Million

Google tracks the attackers under several names, suggesting that apparently separate extortion operations may be connected.

Google calls the groups Falcon, Helix, Pink and Redact and believes they may belong to a broader threat cluster tracked as UNC6671. Researchers said they could be affiliates, splinter groups or users of shared phishing infrastructure.

The attackers generally demand between $750,000 and $3 million, while one cryptocurrency wallet associated with a group received roughly $10 million in Bitcoin during the first months of 2026.

Financial Data Gives Extortionists More Leverage

The attackers have previously targeted manufacturing, healthcare, insurance, technology, transportation, real estate and hospitality companies.

Google observed a more recent shift toward private equity firms and legal and financial organizations because companies involved in mergers, acquisitions, litigation and capital deployment possess particularly valuable confidential information.

Larsen described the attackers’ motivation simply as financial: they identify organizations holding sufficiently sensitive information that executives may pay to prevent its disclosure.

The campaign illustrates an uncomfortable cybersecurity reality. As organizations invest in AI defenses, advanced authentication and increasingly sophisticated security infrastructure, attackers can still succeed by convincing one employee that a phone call is legitimate. The technology protecting an account may be complex, but the route around it can remain distinctly human.

Share
f 𝕏 in
Copied