Google warns of phone-based social engineering attacks targeting financial firms
Google's security researchers have identified hacker groups that are calling employees of large U.S. financial firms to gain access and steal sensitive data. The attackers then use the stolen information to extort victims.
Google's threat intelligence report links four distinct hacker factions—Falcon, Helix, Pink, and Redact—to a broader operation tracked as UNC6671. These actors employ voice phishing, placing calls to personal mobile numbers while impersonating IT support or colleagues to harvest login credentials and multi-factor authentication codes via counterfeit web portals.
The extortion scheme involves public shaming websites that threaten data leaks unless ransoms are paid. While recent attacks focus on private equity and legal entities involved in mergers and litigation, prior campaigns hit manufacturing, healthcare, and tech firms. One associated crypto wallet received roughly $10 million in Bitcoin this year, with individual ransom demands ranging from $750,000 to $3 million.
This trend could significantly disrupt the financial sector's operational security, as traditional employee awareness training may not adequately counter convincing voice-based social engineering. Firms handling sensitive merger data could face heightened reputational and legal risks if breaches occur. The reliance on personal devices for authentication bypasses corporate network defenses, potentially forcing organizations to adopt stricter verification protocols and impacting employee privacy. Ultimately, this may normalize extortion as a primary cyber threat model for high-value targets.