A campaign of voice-phishing intrusions against US hedge funds, private-equity firms and other financial institutions has been attributed to UNC6671, the extortion cluster behind the BlackFile brand, according to Google's Threat Intelligence Group (GTIG). Austin Larsen, a principal threat analyst at GTIG, told BleepingComputer that the group "previously operating under the public brand 'BlackFile'" has "diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon," and that GTIG assesses "a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands." The gang has also gone public, posting a negotiation manifesto on one of its leak sites. Critically, no victim has confirmed a data loss: Point72 reportedly told investors it found no evidence client data was stolen, and Two Sigma said it blocked an attempted intrusion outright.
What Happened
Google published research on Thursday describing groups of hackers breaking into large US financial and investment firms to steal sensitive data and extort victims with the threat of publication. Google did not name the victims. The named victim lists come from press reporting and they do not match each other, so treat the roster as unsettled.
BleepingComputer, citing Reuters and Bloomberg, reports that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel and several unnamed private-equity firms were targeted. TechCrunch, citing Reuters, reports a different and larger set of firms among the victims: Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG. Undercode News repeats the hedge fund roster. The two lists overlap not at all, which most likely reflects two separate Reuters items rather than a contradiction, but no source reconciles them and we will not do it for them.
Victim responses, where they exist, are conservative. Point72 reportedly told investors it had been attacked but had not found evidence that client data was stolen. Two Sigma said it blocked an attempted intrusion and found no indication its systems or data were affected. Millennium declined to comment to BleepingComputer; Citadel declined and referred the outlet to Bloomberg's reporting. Point72 and Two Sigma did not respond to BleepingComputer's requests for comment.
The actor's own statement, quoted by TechCrunch from one of the group's leak sites, reads: "We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement. Respond promptly and in good faith, and the matter is resolved without further incident." BleepingComputer separately updated its report with a statement from the Falcon extortion brand. This is marketing copy from a criminal enterprise and carries no evidentiary weight about what was actually taken.
What Was Taken
Nothing has been confirmed stolen from any named financial firm. That is the single most important line in this brief. The two firms that have spoken publicly both indicated no confirmed data loss, and Google's report describes the objective of the campaign rather than an inventory of its proceeds.
What the sources do establish is what this crew takes when it succeeds elsewhere. Undercode News reports that the primary objective was credential theft against Microsoft 365 and Okta accounts, giving access to internal communications, financial documents and identity management systems. Priwall by mePrism describes the established playbook as mass exfiltration of SharePoint and Salesforce data followed by seven-figure "pay or leak" demands. Femtosec reports a confirmed compromise of FCCI Insurance Group in June 2026 by the Redact brand, with 145 GB of corporate data exfiltrated; that figure comes from a single OTHER-tier source and concerns a different victim in a different sector, so it is a scale reference point, not a number attached to this campaign.
On volume, Priwall cites an unnamed cybersecurity executive, briefed off the record, claiming the group is currently focused on oil and gas operators and private equity firms at a rate of five to ten new victims per week, and that it dispatched a vandal to a victim's home. Priwall states plainly that it could not independently corroborate either the specific incident or the weekly cadence. Neither claim should be treated as established.
Why It Matters
The defensive lesson here is not about a vulnerability. There is no CVE, no patch, no exploited zero-day. Firms with nine-figure security budgets and mature endpoint tooling were reached through a phone call to an employee's personal mobile. As TechCrunch puts it, even in the age of AI-powered autonomous attacks, tricking people into doing things they should not is still producing results.
The second issue is attribution hygiene. This actor is tracked under a dense mesh of names: UNC6671 by Google and Mandiant, CL-CRI-1116 by Palo Alto Networks Unit 42, and Cordial Spider by CrowdStrike, per Priwall, which operates public brands including BlackFile, Redact, Pink, Helix and Falcon. Priwall reports the crew shut its BlackFile leak site in April 2026 and immediately re-emerged under new names; Femtosec describes Redact as previously BlackFile and currently transitioning infrastructure to the Pink brand. BleepingComputer dates BlackFile's emergence to February 2025 with retail and hospitality targeting, and cites Mandiant's report that targeting shifted in July 2026 toward private equity. Sources differ on the exact rebrand chronology. Defenders blocking on a brand name are blocking on a costume change; the intrusion tradecraft persists across all of them.
Third, the sector pivot is deliberate. A hedge fund's cloud tenant contains position data, LP correspondence, deal documents and counterparty terms. That material does not need to be encrypted to be devastating. Extortion-only operations skip ransomware entirely and price the leak threat accordingly.
The Attack Technique
Per Google, as reported by TechCrunch, operators phone employees on their personal cellphones posing as co-workers or IT helpdesk staff, and walk targets into entering credentials and multi-factor codes on spoofed sites. Undercode News describes the same pattern against Microsoft 365 and Okta accounts. Femtosec adds operational detail from the FCCI case: Adversary-in-the-Middle phishing panels, session hijacking to defeat MFA, registration of rogue MFA devices inside the hijacked session for persistence, and programmatic exfiltration via native cloud APIs, which never touches an endpoint agent.
Luxgap's summary of Mandiant's related "ShinyHunters" research documents the same tradecraft in more depth and notes GTIG tracks these operations across clusters UNC6661, UNC6671 and UNC6240. Reported indicators from that work include company-branded phishing portals with domain patterns resembling sso, mysso, internal and okta strings; outbound access via residential VPN and proxy providers including Mullvad, Oxylabs, NetNut, 9Proxy, Infatica and nsocks; a PowerShell User-Agent hitting SharePoint and OneDrive; deletion of "Security method enrolled" notification emails; and abuse of the Google Workspace add-on "ToogleBox Recall" to conceal fraudulent MFA enrollment. Luxgap is an OTHER-tier vendor summary of primary Mandiant and BleepingComputer material, so hunt on these indicators but validate against the vendor originals.
One escalation vector deserves separate treatment. Priwall reports that Unit 42 and GTIG have confirmed BlackFile-lineage actors swatting C-suite executives at their homes to force payment, and cites an FBI public service announcement plus reporting from The Record, CyberScoop and KrebsOnSecurity documenting a broader shift toward physical violence within the "Com" ecosystem the group emerged from. Cyber intrusion followed by physical intimidation is now a documented feature of that ecosystem.
What Organizations Should Do
-
Deploy phishing-resistant MFA. FIDO2 and WebAuthn origin-bound passkeys are the only control on this list that structurally defeats AiTM credential relay, because the authenticator will not sign for an attacker-controlled origin. Luxgap frames this as the expected standard under GDPR Article 32 for SSO and SaaS environments. Prioritize executives, finance, IT and helpdesk staff first.
-
Rebuild helpdesk identity verification. Assume any inbound call requesting a password reset or MFA re-enrollment is hostile. Require out-of-band verification through a channel the caller does not control, and impose a mandatory delay on MFA device registration and recovery-factor changes.
-
Alert on rogue MFA enrollment. New authenticator registration, especially paired with suppression or deletion of enrollment notification emails, is the persistence step in this chain. Make it a paged detection, not a monthly report line.
-
Monitor cloud API exfiltration, not just endpoints. Data leaves via native Graph, SharePoint and Salesforce APIs. Baseline normal bulk-read volumes per account and alert on anomalous programmatic access, including the PowerShell User-Agent pattern against SharePoint and OneDrive.
-
Ingest the published IOCs. Load the residential proxy ranges, phishing domain patterns and TTPs from the GTIG and Unit 42 reporting into SIEM, DNS and proxy logs, EDR and SaaS audit trails, and run them retroactively to surface prior compromise.
-
Brief executives on physical risk. Given documented swatting and home-directed intimidation in this ecosystem, extend incident response planning to executive protection and pre-establish a law enforcement contact before it is needed.
-
Audit for exposed credentials in code. Unrelated to this campaign but relevant to the same sector, SecretRadar reports finding a live Financial Datasets API key committed in plaintext inside a
.envfile in a public repository powering an automated hedge fund application, alongside OpenAI, Groq and Anthropic keys. Scan public repositories for your own organization's secrets.
Sources: Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion... | Google says hackers are calling financial firm employees ... | Wall Street Under Attack: How UNC6671 Turned Voice Phishing Into a... | ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as coun... | BlackFile, Helix, and the Rebrand Treadmill Priwall - mePrism | Cybersecurity Crisis Deepens as UNC6671 Targets Financial Giants an... | Redact Ransomware Steals 145 GB of FCCI Insurance Data | Leak of the Week – Exposure of a Financial Datasets API Key Secret...