Google Alerts: Hackers Targeting Employees of Financial Firms for Extortion
Amid the rise of AI-powered autonomous cyberattacks, traditional hacking techniques that trick victims into making bad choices still prove effective.
According to a report from Google’s security researchers released on Thursday, unidentified hacker groups are breaching major financial and investment firms in the U.S. to obtain sensitive information and threaten to disclose it for extortion purposes.
While the company did not specify the victims, Reuters highlighted that they include well-known private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
The hacking groups, identified by Google as Falcon, Helix, Pink, and Redact, utilize a classic method to infiltrate these firms: by calling employees’ personal cell phones and impersonating colleagues or IT personnel. During these calls, they aim to trick targets into giving away their credentials and multi-factor codes via fake websites, a process referred to as voice phishing or vishing in cybersecurity.
Some of these groups host websites to flaunt their hacks, threatening to publish the stolen data to force victims into paying a ransom—a tactic commonly used by cybercriminals.

“We handle all negotiations professionally. The release of your data is never our first choice; it happens only if there’s a failure to engage, a delay, or a breach of agreement,” one of the websites stated. “Respond promptly and earnestly, and the matter can be resolved without further issues.”
Google’s researchers noted that these groups may belong to a larger entity they monitor called UNC6671. However, it remains unclear whether they are affiliates, independent groups, or are utilizing the same Phishing-as-a-Service infrastructure.
“This could signify a coordinated network of threat actors employing various public extortion brands to compartmentalize their operations, obscure total breach volumes, and minimize any fallout from negotiations,” the report suggested.
According to Google, these hacker groups have previously targeted large corporations in industries such as manufacturing, real estate, healthcare, and insurance, along with technology, transportation, and hospitality, seeking to steal “valuable intellectual property, software source code, or sensitive VIP client information.”
Recently, the hackers have shifted their focus to legal and financial institutions, including private equity firms. “Targeting organizations involved in mergers, acquisitions, capital investments, and litigation may be a strategy to capture high-value corporate and confidential information to enhance their extortion leverage,” noted Google’s researchers.
According to Google, one cryptocurrency wallet linked to one of the hacking groups received about $10 million in bitcoin during the early part of this year, with victims typically facing extortion demands ranging from $750,000 to $3 million.
Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG did not respond to requests for comments.
By purchasing through links in our articles, you can help us earn a small commission. This does not affect our editorial integrity.


