
Google says the attackers used fake help-desk calls and spoofed login pages, then sought $750,000 to $3 million and in some cases threatened victims through public leak sites.
Major Wall Street private-equity and investment firms were swept into a vishing campaign that used phone impersonation and fake login pages to steal passwords and multifactor authentication codes, with Google describing the activity as part of a coordinated extortion effort. Reuters reported the targeted organizations included Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG, while Google's broader tracking identified threat groups including Redact, Pink, Falcon and Helix, which it said may operate under a larger cluster it calls UNC6671. Google said some of the groups run leak sites that threaten to publish stolen corporate data unless victims pay, with ransom demands typically ranging from $750,000 to $3 million. The researchers said a cryptocurrency wallet linked to one group received about $10 million in bitcoin in the first few months of this year, underscoring the scale of the operation. Google said the same actors have also targeted companies across manufacturing, real estate, healthcare, insurance, technology, transportation and hospitality, and that the focus on organizations involved in mergers, acquisitions, capital deployment and litigation suggests an effort to maximize extortion leverage by stealing highly sensitive information.