On Thursday, a ransom-seeking hacker group referred to as UNC6671 targeted over 200 companies over a period of five weeks using voice phishing techniques.

The threat actors built 72 malicious phishing websites impersonating enterprise IT help desks to trap US financial institutions, particularly and give away employee credentials. 

Earlier today, Reuters reported that it analysed Google's data and identified 72 malicious phishing websites targeting major financial firms, including Blackstone, Apollo, Bain Capital, KKR, TPG, CME Group, Bridgewater Associates, Clearlake Capital and Moody's.

Other firms identified on the target list were Uber, Zillow, Levi Strauss, Paul Hastings, Greenberg Traurig, Point72, Citadel, and Two Sigma.

em360tech image

The US financial institutions targeted have not reported any data compromise and have denied Reuters requests to comment on the alleged breach.

The campaign reflects a broader challenge facing financial institutions. As Teradata's Manish Andhy recently told The Security Strategist, more than $3 trillion in illicit funds moves through the global financial system each year, highlighting why cyber resilience and financial crime prevention remain top priorities.

According to Google Threat Intelligence Group (GTIG), which continues to track UNC6671 reported that the hackers are actively initiating compromising malicious activities leading to data theft and extortion. 

However, in May 2026, the hacking group allegedly announced the retirement of the BlackFile extortion brand, but Google found evidence that counters their retirement. UNC6671 continued to function under the aliases of Redact, Pink, Helic, and Falcom.

Also Read: What is Phishing and How can you Defend Yourself Against it?

What is UNC6671?

The name UNC6671 has been attributed to a cyber hacking group by GTIG. Google uses this name to track the threat actors’ malicious activities under the category of data theft and extortion attacks. 

‘UNC’ stands for ‘uncategorised.’ It means that GTIG has been monitoring the group’s ill-intent activities but hasn’t been able to confidently link it to a previously known hacking group. 

However, GTIG has reported that UNC6671 predominantly uses social engineering to target enterprise employees, tricking them into revealing passwords and multi-factor authentication (MFA) codes. They’re especially known for using voice phishing (vishing) hacking techniques to trap employees. 

While vishing is a relatively old form of hacking technique, newer hacking techniques are emerging due to the wide adoption of AI. This hacking group continues to use an older technique. This goes to show that older hacking forms are going to persist. 

UNC6671 uses vishing instead of exploiting technical vulnerabilities by impersonating IT help desks and directs victims to fake login pages to steal credentials and get them to conduct urgent security migrations.

GTIG stated that, significantly, the threat actor often contacts employees via their personal mobile devices. 

Google says hacker group UNC6671 targeted Blackstone, Apollo, KKR and more than 200 companies using voice phishing, fake IT help desks and credential theft.

“These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens,” the statement added. “Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta.”

According to Google, UNC6671 continues to operate despite the apparent retirement of the BlackFile extortion brand in May 2026. Instead of disbanding, the group appears to have rebranded and now conducts extortion campaigns under multiple names, including Redact, Pink, Helix, and Falcon, while using shared infrastructure and similar tactics across its operations.

Why Attacks Rely on Psychology, Not AI

Are you enjoying the content so far?

Whether it's an AI-driven attack or AI fighting AI or an old-school vishing or social engineering cyberattack, one thing remains the same. It’s the problem of visibility. 

Going back to the root of how cyberattacks begin, it could be an employee accidentally clicking on a link or auto-responding to an email or simply being duped by a very convincing hacker impersonating an ally; human mistakes and manipulation have remained consistent in cyber breaches. 

According to IBM’s Cost of a Data Breach Report 2026, human error accounted for roughly 23 per cent of data breaches, while malicious and criminal attacks remained the leading root cause at 55 percent. 

It further found that social engineering and AI-driven manipulation have made human psychology a primary target, driving average breach costs to a record $4.99 million globally. Attackers use psychological tactics like deepfakes and helpdesk impersonation to bypass defences.

Nitay Milner, Co-Founder and CEO of Orion Security, told host Richard Stiennon, Chief Research Analyst at IT-Harvest, on an episode of The Security Strategist podcast, that CISOs need to approach cybersecurity by adopting agentic DLP to prevent old and new kinds of cyberattacks. 

According to the podcast, Agentic DLP can analyse data in context, understanding both the data and the circumstances of its movement.

Milner added that AI can interpret the source, destination, and nature of the data being handled. Such a strategy allows AI systems to differentiate between legitimate business activities and potential data leaks. For instance, if a financial analyst accesses sensitive information to complete a report, AI can identify this as a valid action rather than flagging it as suspicious.