Hackers are calling employees at major U.S. financial firms and stealing login details to extort companies. Here’s how these phone attacks work and how you can better protect yourself online.
Table of Contents
What Happened?
Google published its findings on August 6, 2026. Its researchers track the activity under the name UNC6671 and link it to groups using names including Falcon, Helix, Pink, and Redact.
Reuters identified several companies targeted by related fake websites. They included Blackstone, Apollo Global Management, Bain Capital, Bridgewater Associates, KKR, CME Group, Moody’s, and TPG. Reuters could not confirm which attempted attacks succeeded.
The attackers appear to want valuable corporate and client information they can use to demand money. Google says some related attacks have ended with companies paying ransoms.
Stolen personal information can also remain useful long after the original breach. Criminals may use it to make phishing emails, fake calls, or impersonation attempts seem more convincing.
Many people do not know which past breaches may already include their information.
If you are not sure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Leaked?
The recent campaign mainly targeted large U.S. financial, investment, legal, and professional services companies.
Reuters found fake login websites connected to dozens of financial firms. Its broader review found digital traps aimed at more than 200 companies during five weeks.
However, Google did not name individual victims in its report. Reuters also could not confirm which named companies were successfully hacked.
That means there is no confirmed list of personal information taken from employees or customers at each financial firm.
Across UNC6671 attacks, Google says hackers have targeted confidential corporate information, intellectual property, software code, and sensitive VIP client data.
How Hackers Use Fake IT Calls to Break Into Accounts
The attack starts with voice phishing, also called vishing. This means criminals use phone calls to trick you into sharing information or taking an unsafe action.
Hackers call employees on their personal phones and pretend to work for the company’s IT help desk. In some cases, they can even make the real help desk number appear on caller ID.
The caller says there is an urgent security problem or that the employee must update a passkey or multi-factor authentication.
Then the caller directs the employee to a fake login website that looks like a real company page.
If the employee enters a password or security code, the hackers can capture it immediately and enter the account. They can then use automated tools to copy information from cloud services such as Microsoft 365 and Okta.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safety
At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
