LIVE · cybersecurity feed
Live wire
breach

Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among

zeroday.news ·

A sophisticated hacking campaign has targeted over 200 firms, including major financial institutions, by impersonating IT support staff to steal multi-factor authentication (MFA) credentials. The campaign, tracked by Google Threat Intelligence Group (GTIG) as UNC6671, has operated under several names, including Redact, Pink, Falcon, and Helix, and has been linked to the BlackFile extortion brand.

The attackers employ voice phishing (vishing) techniques, calling employees on their personal mobile phones while posing as the company's IT help desk. In some instances, they spoof the legitimate support number to enhance credibility. They create a false sense of urgency, directing victims to lookalike credential-harvesting websites, such as `[company].createssopasskey[.]com` or `[company].addssopasskey[.]com`, under the pretext of mandatory security migrations, such as enabling FIDO2 passkeys or updating MFA enrollment.

If an employee enters their credentials on these fake sites, the hackers harvest their password and then immediately solicit the second-factor passcode over the phone, hijacking the account before the call concludes. To evade detection, the attackers delete security alerts and password reset notifications from compromised accounts.

After gaining access, UNC6671 utilizes automated tools to exfiltrate data from cloud services like Microsoft 365 and Okta. The group's methods and infrastructure have remained largely consistent despite operating under various extortion brands, suggesting a close operational link between them.

GTIG's analysis indicates that UNC6671, despite announcing the alleged retirement of the BlackFile brand in May 2026, has diversified its operations across multiple extortion fronts. Bitcoin wallets linked to BlackFile received 141.65 BTC, valued at approximately $10.69 million, between January and May 2026. Ransom payments continued even after the publicized shutdown of the BlackFile leak site on May 11, 2026, with significant cashout events observed in late April and early May, confirming uninterrupted financial operations during the rebranding phase.

The attackers typically demand ransoms between $1 million and $3 million, often negotiating discounts of 50-75%. In over half of the tracked cases, victims paid an average ransom of around $750,000.

Targets are selected based on their perceived likelihood of paying to prevent the release of sensitive stolen data, making financial organizations, private equity firms, and law firms particularly attractive. Companies for which malicious subdomains were identified include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. Other targeted entities include Uber, Zillow, Levi Strauss, and law firms such as Paul Hastings and Greenberg Traurig. Point72 Asset Management confirmed it was targeted, and sources indicated attempts against Two Sigma Investments and Citadel.

Greenberg Traurig stated that its security protocols prevented a data breach. Most other named firms either declined to comment or did not respond to inquiries.

Redact, one of the group names, explicitly stated on its darknet site that its hackers are "not politically or morally motivated." Falcon acknowledged an affiliation with Redact but denied any connection to Helix or Pink. The precise relationships between these various groups remain unclear to investigators, although they appear to share common infrastructure. The campaign has repeatedly shifted its focus across sectors, moving to wherever data is deemed valuable enough to generate a ransom payment.

breachfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

security

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]

vulnerability

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

ai

Irregular, firm behind AI hacking incidents, won't say if there were more

A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”

data center technology

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Several cybersecurity incidents are highlighted, including a ban on Chinese data center technology, a supply chain attack on QuickFox VPN, and a phishing breach at IEH Corporation. Additionally, AI-generated content may be impacting Apple's bug bounty program, and a North Carolina port experienced an attack, alongside broader targeting of Wall Street.

security

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]