Financial Firms Under Fire: Hackers Use Fake IT Support to Steal Data

A convincing voice on the phone, a fake help-desk mandate, and a stolen multi-factor passcode later—your corporate cloud account is no longer yours. That’s how a hacking crew tracked by Google’s Threat Intelligence Group (GTIG) as UNC6671 has been quietly siphoning data from more than 200 organizations, including heavyweights like Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s.
A bait-and-switch at scale
The attackers don’t just spam inboxes; they dial employees on personal phones, spoof the real IT help-desk number, and spin a story about a “mandatory security migration” or an “urgent passkey update.” Once the employee lands on a lookalike subdomain—think [company].createssopasskey[.]com—they’re asked for their password. The twist: the caller stays on the line, captures the second-factor code in real time, and logs in before the call ends. By the time the victim hangs up, the intruder is already in the cloud, rifling through Microsoft 365 or Okta. In some cases, firms paid ransoms to keep stolen data from going public.
From extortion brand to extortion brand
Despite rebranding under names such as Redact, Pink, Helix, and Falcon—even after announcing a shutdown of its BlackFile site—the group’s tactics and infrastructure have remained consistent. Google’s analysis shows payments continued into Bitcoin wallets linked to the operation well after the “retirement” announcement, underscoring a transition rather than a retreat. Targets were selected less for size and more for their willingness to pay to avoid leaks, making private-equity firms and financial institutions prime prey.
Why it matters
This isn’t just another phishing alert—it’s a blueprint for bypassing modern MFA defenses. By combining social engineering with caller-ID spoofing and live credential harvesting, UNC6671 has turned the help-desk line into a trojan horse. For financial firms, the message is clear: verify voice requests out-of-band, disable SMS-based second factors where possible, and audit cloud logs for unusual logins. The cost of a single successful call can dwarf the price of layered verification controls.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

