techcrunch.com web signal

Google outs vishing crew hitting Blackstone, Apollo, KKR, CME

7 sources tracking this story
Google Cybersecurity ai-business

TL;DR

  • Google Threat Intelligence Group attributes all four extortion brands (Redact, Pink, Helix, Falcon) to one crew, UNC6671, sharing identical phishing infrastructure across targets.
  • Domain registration accelerated from one every 2.2 days in April to one every 1.6 days by July, with a 7-domain spike on July 20-22 marking the PE targeting sprint.
  • Forensic Microsoft 365 audit logs show UNC6671 spoofing a Microsoft Office user-agent while running Python scripts, a detectable mismatch security teams can flag in real time.

The interesting thing about the vishing crew Google outed this week is who they picked. Not a retailer, not a hospital chain, but the pointy end of American finance. TechCrunch reports that the group Google tracks as UNC6671 has been calling employees at Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG, impersonating IT help desks and walking them onto lookalike single sign-on portals to hand over credentials and MFA codes in real time.

The logic of the target list is uncomfortably clean. Google's principal threat analyst Austin Larsen put it to Reuters as an exercise in leverage: 'they think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.' The economics back that up. One cryptocurrency wallet linked to the group received roughly $10 million in Bitcoin during early 2026, and typical ransom demands run $750,000 to $3 million per victim.

The technique is worth understanding because it is not novel, just relentlessly well-executed. In Google Cloud's own writeup, the group (operating under the 'BlackFile' brand) rings employees' personal cellular phones to bypass security tooling, pitches a mandatory passkey migration or MFA update, and runs an adversary-in-the-middle site that pipes the victim's password and MFA code straight into the real Okta or Microsoft 365 login. Once in, they register a new attacker-controlled MFA device for persistence and start scripting exfiltration from SharePoint and OneDrive. In one case, Google says the operator downloaded over a million individual files from a single victim's tenant.

Worth flagging that most of the specifics here are Google's telemetry rather than confirmed breach disclosures. None of the named firms have publicly said what, if anything, was taken, and the reporting does not pin down which victims paid. Google also notes the BlackFile data leak site went offline in late April 2026 and briefly returned on May 11 with a message that 'BlackFile is shutting down… under this name,' which Google itself reads as a probable transition rather than a real exit. It fits a pattern we have been tracking closely, with 321 cybersecurity stories in the last 90 days alone.

If there is an upside, it accrues to the vendors of phishing-resistant hardware keys and to the CISOs who have been trying, and failing, to get budget for vishing simulations and stricter help-desk callback verification. A named list of PE giants tends to move procurement faster than a year of tabletop warnings.

What others are reporting

Coverage cluster as of 8h after publish

  1. Google Cloud Blog (Threat Intelligence) Read →

    First-party Google GTIG report with Microsoft 365 audit log forensics, User-Agent mismatch IOCs, ransom note evolution from Tox to branded Session-app, and SecOps detection rules.

    UNC6671 leverages vishing combined with victim-branded credential harvesting sites to compromise SSO accounts and capture MFA.
  2. Google Cloud Blog (Threat Intelligence) Read →

    Documents the pivot from BlackFile to four simultaneous extortion brands, maps shared infrastructure, tracks 141.65 BTC across 18 wallets, and quantifies domain provisioning acceleration.

    UNC6671 has rebranded from BlackFile to REDACT while diversifying its extortion operations across multiple brands, including FALCON, HELIX, and PINK.
  3. Reuters Read →

    Reuters reverse-engineered 72 malicious domains to map attack infrastructure, confirming company-specific phishing pages were built for each named target firm.

    Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us. (Lee Clark, Retail and Hospitality ISAC)
  4. BleepingComputer Read →

    Adds Falcon's public rebuttal disputing Mandiant's unified-group theory on their own leak site, plus confirmation Mandiant is supporting several dozen compromised organizations.

    While previously operating under the public brand 'BlackFile,' UNC6671 has diversified its extortion operations across multiple public brands.
  5. SiliconANGLE Read →

    Provides the full targeting evolution timeline and notes the crew reaches employees on personal mobile numbers with spoofed legitimate helpdesk caller IDs.

    When the goal of cyber criminals is financial gain it is only logical that investment firms that manage sensitive financial information are attractive targets.
  6. Gizmodo Read →

    Frames the campaign as a consequence of permissive AI voice-cloning regulation, situating it within the broader consumer harm debate around voice synthesis tools.

    AI is arguably the most enabling tool ever invented for technologically-enabled scams.

Shared on Bluesky by 1 AI expert