Private Equity Cybersecurity: Inside the UNC6671 Vishing Extortion Scheme

Vishing
·
Summarize with:
Private Equity Firms Vishing

On August 6, 2026, Google Threat Intelligence Group published an analysis of UNC6671, a cluster of extortion operations running help desk vishing against financial services, private equity, and professional services firms. The technique is not new. The targeting is. Between April and July 2026, UNC6671 narrowed from broad enterprise credential harvesting to firms holding M&A, capital deployment, and litigation data. This note breaks down the attack scheme and the controls that stop it. This follows the recent coordinated vishing wave that hit Citadel, Two Sigma, Point72 and Millennium. 👇

Key Takeaways

  • Google Threat Intelligence Group tracks UNC6671 as a coordinated actor operating five extortion brands: BlackFile, Redact, Pink, Helix, and Falcon.
  • The intrusion chain is identity-centric. No malware, no zero-day. A phone call, a spoofed passkey enrollment portal, and an adversary-in-the-middle proxy that captures both credentials and the MFA token.
  • Callers dial employees on personal mobile numbers, outside corporate security visibility, and in recent cases spoof the legitimate help desk number.
  • Targeting narrowed to private equity firms, law firms, and financial rating agencies by July 2026, with infrastructure provisioned at roughly one domain every 1.6 days.
  • Initial demands run $1M to $3M. Google observed final settlements averaging $750,000 in more than half of tracked cases.
  • Phishing-resistant authenticators and out-of-band callback are the two controls that break this chain. Awareness training through simulated tests is what makes both of them survive contact with a persuasive caller.

What is UNC6671 and which firms were targeted?

UNC6671 is the designation Google Threat Intelligence Group uses for a threat cluster that has operated under five successive extortion brands. GTIG's telemetry showed the operation did not disband. It diversified across Redact, Pink, Helix, and Falcon, with shared phishing templates, overlapping victim targeting, and reused root domains linking the brands together.

Google did not name victims. Reuters subsequently reported that targets included Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG. Those firms have not confirmed the reporting, and CME Group declined to comment. Treat the victim list as reported rather than verified. The attack scheme itself is documented directly by Google.

Read the full Google Threat Intelligence Group analysis →

How does the vishing attack chain works?

The chain is short, entirely identity-based, and leaves almost no endpoint forensics behind.

  1. Reconnaissance and infrastructure staging: The actor registers a generic root domain built from enterprise authentication vocabulary, pairing terms like passkey, MFA, or SSO with a verb. Examples include passkeyhelpdesk[.]com and createssopasskey[.]com. A victim-specific subdomain is then added, so the employee sees their own company name in the URL.
  2. The call: An operator phones the employee, frequently on a personal mobile number that sits outside corporate controls. In recent intrusions the actor spoofed the organization's legitimate help desk number. The pretext is a mandatory, urgent security migration: enable FIDO2 passkeys, or re-enroll your MFA.
  3. Credential and token capture: The caller walks the employee to the lookalike subdomain. Adversary-in-the-middle infrastructure sitting behind the page relays the session in real time, capturing the password and the MFA response together.
  4. Persistence: With a live session established, the actor enrolls their own MFA device and authenticates onward through residential proxy pools matched to the employee's geography.
  5. Automated SaaS exfiltration: Scripts pull data directly out of Microsoft 365 and Okta. Google observed scripting user agents including python-requests and WindowsPowerShell performing high-volume file access.
  6. Extortion: Stolen data is published or threatened on a brand-specific leak site.

What’s new?

Since the recent hedge fund vishing wave, attackers have added new layers of deception and evasion. Help desk number spoofing now allows calls to appear to come from a legitimate internal number, removing a key verification signal for employees. UNC6671 has also turned inbox evasion into a routine tactic, using compromised mailboxes to trigger password resets on non-SSO applications before deleting reset confirmations, MFA change notifications and security alerts. At the same time, the operation’s use of five different names can obscure the true scale of the campaign, meaning threat briefings organized by individual brands may significantly underestimate the actor’s overall reach.

Why are private equity and financial services firms the target?

Google's domain registration data shows a deliberate progression in target selection across 2026.

Period Target profile Apparent objective
April to May 2026 Manufacturing, real estate, healthcare, insurance High-volume credential harvesting across large enterprises
June 2026 Technology, transportation, hospitality Intellectual property, source code, VIP client data
July 2026 onward Private equity, law firms, financial rating agencies M&A, capital deployment and litigation data for maximum extortion leverage

The logic is straightforward. A private equity firm holds deal documents whose premature disclosure carries consequences far beyond the firm itself: LP commitments, counterparty positions, regulatory exposure, and live transaction terms. That asymmetry is what raises a ransom demand. Google recorded roughly one new domain every 1.6 days across June and July, up from one every 2.2 days in April and May, with seven domains provisioned inside a single 72-hour window in late July.

Google tracked 18 BlackFile Bitcoin wallets from January to May 2026, totaling 141.65 BTC (~$10.69M at transaction time), with payments continuing after the May 11 shutdown announcement—indicating operations never paused during the rebrand. Initial ransom demands typically ranged from $1M–$3M, but negotiations cut them by 50%–75%; in over 53% of cases, final payments averaged $750,000.

How do private equity firms defend against vishing?

A vishing call cannot be detected by your email gateway or your EDR. The controls that work are procedural, identity-layer, and behavioral. This is a compact recap of the action items from our CISO playbook on AI vishing attacks and finance team defense.

Priority Action item Owner
P0 Out-of-band callback to a pre-registered number for any voice request touching credentials, access, or money movement IT help desk, treasury
P0 Phishing-resistant authenticators (FIDO2 keys, passkeys, platform authenticators) across all SSO and IdP environments, so origin binding renders lookalike domains useless Identity, IT operations
P0 Standing policy that unsolicited calls to personal devices claiming to be IT are ignored and reported Security, HR
P1 Hardened identity verification for help desk MFA resets and enrollment IT operations
P1 Quarterly vishing simulation for deal teams, finance, treasury, executive assistants, and help desk staff Security awareness
P1 Alerting on new MFA device enrollment, anomalous session geolocation, and residential proxy authentication Security operations
P2 Tabletop exercise simulating a successful impersonation call, including the synthetic media branch CISO, IR lead
  • Callback is the control that survives everything else failing. An attacker can spoof your help desk number, clone a voice, and hold a fluent conversation under pressure. They cannot answer the number already on file.
  • Phishing-resistant MFA is the technical equivalent. WebAuthn binds the authenticator cryptographically to the legitimate domain, so an employee who reaches a lookalike subdomain simply cannot complete authentication there, regardless of how convincing the caller was.
  • Neither control works if staff have never encountered the pretext. Recognition comes from exposure, not from a policy document. Employees who have already taken a convincing simulated call identify the real one faster, and more importantly, they escalate it.

UNC6671 is the identifier Google Threat Intelligence Group uses for a threat cluster conducting help desk voice phishing followed by data theft extortion. GTIG assesses that the same actors operate five public extortion brands: BlackFile, Redact, Pink, Helix, and Falcon, linked by shared phishing infrastructure, identical credential harvesting templates, and overlapping victim targeting.

Google did not name victims in its analysis. Reuters reported that targets included Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG. These names come from press reporting rather than from Google's technical analysis or from confirmation by the firms themselves.

Standard MFA does not. The adversary-in-the-middle proxy captures the one-time code or push approval in the same session as the password. Phishing-resistant authenticators do stop it, because WebAuthn enforces cryptographic origin binding between the authenticator and the legitimate domain, which a lookalike subdomain cannot satisfy.

Personal devices sit outside corporate telephony, mobile device management, and security monitoring. A call to a personal number produces no corporate log, cannot be filtered by enterprise controls, and reaches the employee in a context where they are less likely to apply workplace verification habits.

Run measured simulations against the specific populations attackers target, which for private equity means deal teams, finance, treasury, executive assistants, and the help desk. Arsen is a social engineering simulation and security awareness training platform covering phishing, vishing, and smishing, and produces per-population susceptibility and reporting metrics suitable for board, LP, and regulatory reporting.


Test your teams against the calls actually being made

UNC6671 is provisioning new infrastructure every 1.6 days and dialing private equity, banking, and financial services staff on their personal phones. Find out how your deal, treasury, and help desk teams respond before an operator does.



Can your team spot a vishing attack?

Test them and find your blind spots before attackers do.

Don't miss an article

No spam, ever. We'll never share your email address and you can opt out at any time.