Google Warns of Phone-Based Hacking Campaign Against Global Financial Firms

NewsDais

August 7, 2026

Google Warns of Phone-Based Hacking Campaign Against Global Financial Firms

Google has uncovered a large hacking campaign against dozens of major American financial institutions. The attackers contacted employees by phone and tricked them into handing over login details.

Targeted companies include Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG, and Moody’s. The attackers also built fraudulent websites that looked like services used by each organisation.

Google Threat Intelligence Group continues to investigate the group behind the campaign. The group is known as UNC6671 and has been linked to data theft extortion.

The warning matters because the group was earlier believed to have ended its operations. Its BlackFile brand was reportedly retired in May 2026, but Google says the group has not disappeared.

Instead, the operators have shifted to multiple extortion fronts. These include Redact, Pink, Helix, and Falcon.

How the Attackers Work

Fake Calls From IT Support

The hackers use voice phishing, or vishing, as the first step. They pose as IT helpdesk staff and tell employees that urgent security tasks must be completed.

Many of these calls go directly to personal mobile phones. This approach lets the attackers reach employees outside the office environment.

Malicious Login Portals

The callers then direct employees to spoofed login pages. These pages appear authentic but are controlled by hackers.

Google said the attackers use Adversary-in-the-Middle infrastructure. This system captures usernames, passwords, and multi-factor authentication codes.

Once the credentials are captured, the attackers gain access to the employee’s account. They can then move through the company’s cloud systems.

Automated scripts help the hackers copy data from services like Microsoft 365 and Okta.

Scale of the Campaign

The operation is wide in its reach. In the past five weeks, attackers prepared malicious websites for more than 200 companies.

An analysis of 72 malicious websites linked to the campaign showed traps for those firms. Each site was tailored to a specific company or group.

This level of preparation shows that the hackers had clear information about their targets.

Shift Toward High-Value Sectors

Google found that the hackers recently moved toward private equity firms, law firms, and rating agencies. These organisations often hold sensitive client and financial data.

The list of targets includes major names from different industries. Uber, Zillow, Levi Strauss, and law firms Paul Hastings and Greenberg Traurig were also targeted.

Hedge funds Point72, Two Sigma, and Citadel were among those approached by the hackers.

Extortion and Ransom Payments

Google described the attackers as ransom-seeking groups. The campaign is designed to steal data and then demand payment for its return or silence.

Some attacked companies reportedly paid ransoms. Google did not disclose which companies chose to pay.

Google did not say whether those payments reduced damage for any firm.

New Brands After BlackFile

The hacking group originally worked under the BlackFile extortion brand. In May 2026, that brand was reported to have retired.

Google’s latest findings show that the group continued operating under different names. The new brands include Redact, Pink, Helix, and Falcon.

This change explains why threat tracking remained important even after BlackFile disappeared.

Why the Attack Worked

Cybersecurity experts say the attack combined technical and human elements. The phone call made the request seem legitimate.

Lee Clark of the Retail and Hospitality ISAC said attackers trick the guard instead of breaking the fence. He noted that modern security is strong, so criminals focus on fooling people.

Austin Larsen of Google said the motive is money. He explained that the targeted firms hold sensitive data, so they may be willing to pay.

Attackers Contacted Personal Devices

One notable detail is the use of personal phone numbers. Many employees expect security alerts through company channels, not personal calls.

This method lowers the employee’s guard. A personal call can feel more direct and urgent.

The attackers used this urgency to push employees into acting quickly.

Cloud Services Became the Main Target

Once inside the network, the attackers focused on cloud environments. Microsoft 365 and Okta were the main services mentioned in the report.

These platforms store email, documents, and identity controls. Access to them gives hackers a broad view of a company’s operations.

Google said automated scripts were used to take data from these services. This allowed large-scale theft without manual effort.

Multi-Factor Authentication Can Be Bypassed

Many companies rely on multi-factor authentication to protect accounts. The attack shows that this security measure is not foolproof.

By intercepting tokens, the hackers can enter systems even when users provide additional codes. The process happens in real time during the login attempt.

Employees may believe they are logging into a legitimate service, but the attackers are simply forwarding the data to the real system.

Companies Affected Across Sectors

The campaign covered more than financial institutions. Retail, real estate, and entertainment companies also appeared on the target list.

Uber, a ride-hailing company, and Zillow, a property platform, were both affected. Levi Strauss, a clothing company, was also included.

Law firms Paul Hastings and Greenberg Traurig faced similar attacks. Their client data is highly sensitive.

Security Researchers React to the Findings

The findings highlight the growing problem of vishing. Security teams have spent years building digital defenses, but phone-based attacks bypass those tools.

Clark’s statement supports this view. He said the guards, not the fence, are the target.

Larsen’s comments reinforce the financial motive behind the campaign. Data is the asset the attackers want to exploit.

Avoiding Panic, Building Defense

Google’s report is not meant to create panic. It is a warning that helps companies improve their defenses.

Organisations should train employees to question unexpected calls. Security policies should lay out clear steps for verifying such requests.

Every company using cloud services should review its authentication processes.

What Employees Should Look For

An unexpected call from IT support should be treated with suspicion. Employees should ask for a ticket number or an official email before sharing information.

Login pages reached through phone links may be fake. Users should always type the address of a known service directly into the browser.

If a system asks for a multi-factor authentication code, the employee must confirm that the request comes from the actual service.

Impact on Trust in IT Support

Vishing attacks can damage trust in genuine IT support teams. Employees may become hesitant to respond to legitimate security requests.

Companies can address this by establishing clear communication procedures. For example, IT staff can verify their identity through official internal channels.

Clear policies reduce confusion and help employees spot fraudulent calls.

Google Continues Tracking the Threat Group

Security researchers identified 72 dangerous websites so far. Google said it continues to track UNC6671 actively.

The group has shown that it can quickly change its methods. Google will keep monitoring for new domains associated with the campaign.

Attackers may design new pages for additional firms, but Google did not provide such details.

Previous BlackFile Activity

BlackFile was an extortion brand linked to the same hackers. Its alleged retirement led some observers to think the threat had ended.

Google’s analysis shows that the group simply changed names. The underlying infrastructure and methods remain active.

This pattern is common among cybercriminal groups. Renaming helps them avoid scrutiny and continue earning money.

Law Firms and Ratings Agencies Under Pressure

Law firms and ratings agencies hold confidential information about deals and companies. That makes them attractive to extortionists.

Paul Hastings and Greenberg Traurig are large legal practices. Moody’s is a major agency that provides credit ratings.

The attackers are focused on organisations that hold valuable data.

Need for Cloud Monitoring

Companies should monitor their cloud platforms for unusual activity. A single compromised account can lead to broad data loss.

Automated scripts make exfiltration fast. Security teams need alerts for large downloads or access from unknown locations.

These measures can help stop an attack before data leaves the network.

Final Takeaways

The Google warning reveals a serious and active threat. Hackers are using phone calls to gain access to major companies.

The targeted list shows that even famous financial firms can be caught in such campaigns. No company should assume it is too small or too protected.

Google’s tracking of the group will continue. Businesses should use this warning to strengthen their own defenses.

Leave a Comment