Google's security team says a set of unknown hackers is using a familiar but effective tactic to target major U.S. financial and investment firms: voice phishing, or vishing. The attackers reportedly call employees on personal phones, pose as coworkers or IT support, and try to capture login details and multi-factor authentication codes through spoofed websites.
In a report published Thursday, Google said the campaign is aimed at stealing sensitive corporate data that can later be used for extortion. The company did not publicly name the victims, but the activity has been linked to several prominent private equity and financial organizations, including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG.
Google tracks the groups behind the activity under labels such as Falcon, Helix, Pink, and Redact, and says they may be connected to a broader cluster it calls UNC6671. Researchers believe the operators could be sharing infrastructure or working as coordinated brands within a larger ecosystem.
According to the report, some of these groups run public websites that advertise stolen data and pressure victims into paying. Google also noted that the same actors have previously focused on sectors including manufacturing, healthcare, insurance, real estate, transportation, hospitality, and technology, often seeking intellectual property, source code, or confidential client information.
The researchers said the recent focus on legal and financial organizations suggests a strategy centered on high-value data and stronger leverage in negotiations. Google also reported that a cryptocurrency wallet tied to one of the groups received about $10 million in Bitcoin earlier this year, while typical ransom demands range from $750,000 to $3 million.
This case shows how social engineering remains a powerful tool in cybersecurity, and how awareness training may become even more important as digital threats grow more sophisticated.