techcrunch.com web signal

Google outs vishing crew hitting Blackstone, Apollo, KKR, CME

google cybersecurity ai-business

TL;DR

  • Google tied a vishing crew to attacks on Apollo, Bain Capital, Blackstone, Bridgewater, CME Group, KKR, Moody's and TPG.
  • One cryptocurrency wallet linked to the group received about $10 million in Bitcoin in early 2026, with typical ransoms of $750,000 to $3 million.
  • Google tracks the actor as UNC6671, operating under the 'BlackFile' brand and using adversary-in-the-middle sites to steal SSO credentials and MFA codes.

The interesting thing about the vishing crew Google outed this week is who they picked. Not a retailer, not a hospital chain, but the pointy end of American finance. TechCrunch reports that the group Google tracks as UNC6671 has been calling employees at Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG, impersonating IT help desks and walking them onto lookalike single sign-on portals to hand over credentials and MFA codes in real time.

The logic of the target list is uncomfortably clean. Google's principal threat analyst Austin Larsen put it to Reuters as an exercise in leverage: 'they think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.' The economics back that up. One cryptocurrency wallet linked to the group received roughly $10 million in Bitcoin during early 2026, and typical ransom demands run $750,000 to $3 million per victim.

The technique is worth understanding because it is not novel, just relentlessly well-executed. In Google Cloud's own writeup, the group (operating under the 'BlackFile' brand) rings employees' personal cellular phones to bypass security tooling, pitches a mandatory passkey migration or MFA update, and runs an adversary-in-the-middle site that pipes the victim's password and MFA code straight into the real Okta or Microsoft 365 login. Once in, they register a new attacker-controlled MFA device for persistence and start scripting exfiltration from SharePoint and OneDrive. In one case, Google says the operator downloaded over a million individual files from a single victim's tenant.

The honest caveat is that most of the specifics here are Google's telemetry rather than confirmed breach disclosures. None of the named firms have publicly said what, if anything, was taken, and the reporting does not pin down which victims paid. Google also notes the BlackFile data leak site went offline in late April 2026 and briefly returned on May 11 with a message that 'BlackFile is shutting down… under this name,' which Google itself reads as a probable transition rather than a real exit.

If there is an upside, it accrues to the vendors of phishing-resistant hardware keys and to the CISOs who have been trying, and failing, to get budget for vishing simulations and stricter help-desk callback verification. A named list of PE giants tends to move procurement faster than a year of tabletop warnings.