Even with advanced cyber threats, hackers are sticking to tried-and-true tricks by calling financial firm employees. Using vishing—a form of phishing via phone—they trick targets into revealing their credentials or multi-factor authentication codes on fake websites.
The attackers, dubbed by Google as Falcon, Helix, Pink and Redact, operate in groups that may be part of a larger collective called UNC6671. Some run leak sites to extort victims. Bitcoin wallets linked to these hackers have seen millions stolen, with demands ranging from $750,000 to $3 million.
These criminals target a wide array of companies including manufacturing and real estate firms, private equity groups like Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s and TPG. The goal is often sensitive financial or intellectual property data that can be used for extortion.
The hackers seem to focus on organizations involved in mergers, acquisitions, capital deployment and litigation, aiming to maximize the value of their ransom demands. This strategy highlights an enduring vulnerability in human trust and cybersecurity defenses alike.







