Attackers Impersonate IT Support to Breach Leading Financial Companies

Published July 28, 2026

Callers pretending to be internal IT help desk staff have been phoning employees at Blackstone, Bridgewater Associates, Apollo Global Management, and dozens of other financial firms to steal their login codes. Once in, the attackers took data and demanded ransom, and some firms reportedly paid.

Report priority
Critical
Victim
Blackstone

What is known

  • An attacker calls an employee's personal cell phone, sometimes with the caller ID faked to match the real help desk number, and claims an urgent security migration requires the employee to reset their password or MFA on a lookalike website.
  • When the employee types in the code, the attacker captures it live and takes over the account before the call ends.

What to do

If you work at a financial firm and got an unexpected call on your personal phone from someone claiming to be your company's IT help desk asking you to reset your password or MFA on a link they sent, treat it as this campaign.

Report any such call to your real IT or security team through a known internal channel, never the number the caller gives you, and never enter your password or MFA code on a page reached through an unsolicited call or text.

Reported details

An employee at a financial firm gets a call on their personal phone from someone claiming to be internal IT support. The caller says a mandatory security update requires an immediate passkey or MFA reset and sends a link to a fake company login page. The employee enters their password and reads out the one-time code, and the attacker uses it instantly to log into the real account, then deletes the security alert emails so the employee never notices.

Google's Threat Intelligence Group tracks the actor as UNC6671, which ran the BlackFile data theft extortion brand and, despite an announced retirement of that brand in May 2026, has continued operating under names including Redact, Pink, Helix, and Falcon. The group relies on vishing calls to employees' personal mobile numbers, impersonating IT helpdesk staff and sometimes spoofing the legitimate support line, to drive victims to credential harvesting pages that capture both password and live MFA codes, hijacking SSO sessions before the call ends. Compromised accounts are then used for data theft extortion, and the group deletes security alert and password reset notifications to delay detection.

References