A single extortion crew hiding behind four brand names used phone calls and fake passkey portals to hunt the Wall Street’s financial giants
The most alarming cyberattack wave to hit American finance this year did not begin with malicious code slipping past a firewall. It began with a ringing phone.
A con call, not a code exploit
The technique is known in the security trade as voice phishing, or vishing. According to Google’s Threat Intelligence Group (GTIG), callers posing as internal IT helpdesk staff ring employees on their personal mobile phones, deliberately sidestepping corporate security tooling. In some recent cases the attackers even spoofed the legitimate helpdesk number on caller ID, lending the ruse an air of authenticity.
The pretext is always urgent and always plausible. The caller claims the company is running a mandatory security migration, typically enrolment in FIDO2 passkeys or an update to multi factor authentication.
The employee is then steered to a lookalike login page hosted on a domain with a reassuring name such as passkeyhelpdesk or secure-passkey, with the victim company’s name appended as a subdomain.
Behind that page sits adversary in the middle infrastructure that intercepts the username, password and one time authentication codes in real time, hijacking the session before the call has even ended.
One gang, four masks
Google said the hackers operate under a range of names, including Redact, Pink, Falcon and Helix. Behind the theatrical branding, GTIG tracks a single cluster it calls UNC6671, previously known by the extortion brand BlackFile, which supposedly retired in May 2026.
The rebranding saga has descended into cybercriminal soap opera. In late June, the Redact operators published a statement claiming the original BlackFile brand had been hijacked by an exiled affiliate who staged the shutdown to confuse threat analysts and cyber insurance negotiators. After Google’s report landed, the Falcon crew rushed out a denial on its data leak site, as reported by BleepingComputer.
“Falcon is a Redact affiliate. We are exclusively a Redact affiliate. We are not affiliated with, connected to, or under the same umbrella as Helix, Pink, or any other group named in Mandiant’s reporting,” the threat actors posted on their data leak site.
Google is unmoved by the denials. Austin Larsen, principal threat analyst at Google’s “hreat Intelligence Group,” set out the firm’s assessment in comments to BleepingComputer. GTIG’s position is that a single core intrusion group is driving the helpdesk vishing and cloud data theft across all of these public extortion brands.
Larsen also drew a careful line between this cluster and an older, better known adversary whose tradecraft it closely resembles.
“While the helpdesk vishing and Adversary-in-the-Middle authentication interception share similarities with methods historically associated with Scattered Spider (UNC3944), GTIG tracks this specific infrastructure, domain registration pattern, and multi-brand extortion network as UNC6671,” Larsen told BleepingComputer.
The firm concedes that splintered affiliates or a shared phishing as a service ecosystem remain plausible alternative explanations. Even so, the overlaps are striking.
The pivot to private equity
What makes the July wave notable is not the method but the target list. Google’s analysis of domain registrations shows a deliberate evolution. Between April and May the group cast a wide net across manufacturing, healthcare, real estate and insurance.
In June it moved towards technology, transport and hospitality firms holding intellectual property and VIP client data. By July the crosshairs had narrowed onto private equity firms, law firms and financial ratings agencies, organisations sitting on merger documents, capital deployment plans and live litigation files.A buyout firm with a live deal in the data room, or a law firm holding privileged litigation strategy, has every incentive to settle quietly rather than watch confidential material appear on a dark web leak site.
Reuters reverse engineered many of the company specific traps by running the 72 malicious websites Google listed through web intelligence platforms DomainTools and urlscan, which flagged subdomains tailored to each firm.
In all, the phishing infrastructure has been linked to more than 200 organisations. Beyond the private equity names, the target set included the law firms Paul Hastings and Greenberg Traurig, while Reuters and Bloomberg reported that hedge funds including Point72, Two Sigma and Citadel were targeted in related attacks. KKR, Bain Capital, CME, TPG and Apollo declined to comment.
Follow the Bitcoin
The economics explain the persistence. Working with blockchain researcher ZachXBT, GTIG reviewed 18 Bitcoin wallets linked to BlackFile and put hard numbers on the trade.
“Between January and May 2026, GTIG tracked over USD 10.6 million USD in Bitcoin payments to group wallets. While initial demands reach upwards of USD 3 million, operators routinely settle for around USD 750,000 after negotiations,” Larsen said.
Google’s report adds precision. The wallets received 141.65 BTC between January and May 2026, negotiated discounts typically ran to between 50% and 75% of the opening demand, and some companies, which Google did not name, paid.
The operational tempo is accelerating in step. New phishing domains appeared at a rate of one every 1.6 days through June and July, up from one every 2.2 days in the spring, with seven domains stood up in a single 72 hour burst in late July.
Why it matters
The seriousness of this campaign lies in what it exposes. The targeted firms collectively manage trillions of dollars and spend lavishly on security, yet the attackers needed no zero day exploit, only a convincing voice and a well built fake page.
“Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” Clark said.
“That human element consistently is why this has exploded in the way it has,” he added.
The potential harms go well beyond ransom cheques. Stolen deal documents could enable insider trading, sabotage live transactions, expose limited partners’ confidential information and shake counterparty trust across markets where discretion is the entire business model. Quiet payments also feed a criminal economy that keeps reinvesting in better infrastructure.
Google’s prescription is blunt. Deploy phishing resistant authentication such as hardware keys and passkeys that refuse to work on lookalike domains, restrict logins to managed devices and trusted networks, and train staff to treat any unsolicited helpdesk call as guilty until proven innocent. The fence, in other words, is fine. It is the guard at the gate who needs backup.
