Even with advanced automated cyber threats making news, basic social engineering tricks still deliver big results for online criminals. Groups of unidentified hackers are actively breaching major financial and investment firms across the United States. They steal sensitive internal data and threaten to publish the stolen files unless victims pay steep extortion ransoms. Security researchers at Google detailed these ongoing attacks in a fresh intelligence report published Thursday.
While Google did not officially name the victim companies, news reports identified several major private equity firms and financial institutions on the target list. Targets include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
The hackers rely on simple phone calls to carry out their intrusions. Google security teams track these threat groups under names like Falcon, Helix, Pink, and Redact. Cybercriminals place phone calls directly to employees’ personal cell phones, pretending to be co-workers or internal helpdesk staff. During these conversations, callers trick workers into typing account passwords and multi-factor authentication codes into fake, look-alike websites. Security specialists refer to this voice-based phishing technique as vishing.
Once hackers gain access to corporate networks, they steal sensitive records and post ransom demands on public extortion websites. On these sites, attackers threaten to leak confidential internal files if victims refuse to negotiate. One active leak site warns targets that publishing stolen corporate records is the direct consequence of refusing to pay or stalling negotiations.
Google analysts suspect these distinct hacking groups operate under a larger umbrella network or share the same underlying technical platform. Researchers track this overall activity cluster under the identifier UNC5671. It remains unclear if these outfits operate as independent splinter crews or if they simply rent the same phishing infrastructure to run separate extortion brands. Managing multiple extortion sites helps attackers hide overall breach volumes while running simultaneous extortion schemes.
Before setting their sights on private equity firms, these same hacking groups targeted major corporations across manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality sectors. Attackers focused on stealing valuable intellectual property, source code, and confidential client lists.
Recently, attackers shifted focus toward law firms and private equity groups involved in major corporate mergers, acquisitions, and litigation cases. Focusing on high-value corporate deals gives hackers massive leverage when demanding heavy ransom payments from corporate targets.
Blockchain tracking shows that one cryptocurrency wallet tied to these attacks collected around $10 million in Bitcoin during the first few months of this year. Attackers typically demand ransom payments ranging from $750,000 to $2 million per victim. Representatives from CME Group declined to comment on the breach reports, while other targeted financial firms did not respond to requests for comment.

