Attackers Impersonate IT Support to Breach Leading Financial Companies
Callers pretending to be internal IT help desk staff have been phoning employees at Blackstone, Bridgewater Associates, Apollo Global Management, and dozens of other financial firms to steal their login codes. Once in, the attackers took data and demanded ransom, and some firms reportedly paid.
- Report priority
- Critical
- Victim
- Blackstone
What is known
- An attacker calls an employee's personal cell phone, sometimes with the caller ID faked to match the real help desk number, and claims an urgent security migration requires the employee to reset their password or MFA on a lookalike website.
- When the employee types in the code, the attacker captures it live and takes over the account before the call ends.
What to do
If you work at a financial firm and got an unexpected call on your personal phone from someone claiming to be your company's IT help desk asking you to reset your password or MFA on a link they sent, treat it as this campaign.
Report any such call to your real IT or security team through a known internal channel, never the number the caller gives you, and never enter your password or MFA code on a page reached through an unsolicited call or text.
Reported details
An employee at a financial firm gets a call on their personal phone from someone claiming to be internal IT support. The caller says a mandatory security update requires an immediate passkey or MFA reset and sends a link to a fake company login page. The employee enters their password and reads out the one-time code, and the attacker uses it instantly to log into the real account, then deletes the security alert emails so the employee never notices.
Google's Threat Intelligence Group tracks the actor as UNC6671, which ran the BlackFile data theft extortion brand and, despite an announced retirement of that brand in May 2026, has continued operating under names including Redact, Pink, Helix, and Falcon. The group relies on vishing calls to employees' personal mobile numbers, impersonating IT helpdesk staff and sometimes spoofing the legitimate support line, to drive victims to credential harvesting pages that capture both password and live MFA codes, hijacking SSO sessions before the call ends. Compromised accounts are then used for data theft extortion, and the group deletes security alert and password reset notifications to delay detection.
References
- docs.gitlab.com · patch-release-gitlab-18-11-9-released (patches) patch release notes
- cwe.mitre.org · 506.html vdb entry
- securityaffairs.com · researchers-discover-hidden-backdoor-in-20-router-models-allowing-remote-root-access.html SecurityAffairs
- vulncheck.com · zbt-endlessdoors SecurityAffairs
- github.com · search SecurityAffairs
- theregister.com · 5283794 SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- thehackernews.com · ai-recommendation-poisoning-how-ask-ai.html TheHackerNews
- socket.dev · free-business-plan-upgrades-for-open-source Socket
- opensource.org · licenses Socket
- socket.dev · aws-security-hub-socket Socket
- aws.amazon.com · security-hub Socket
- aws.amazon.com · aws-security-hub-extended-adds-supply-chain-security Socket
- socket.dev · anthropic-claude-pypi-malware Socket
- anthropic.com · investigating-incidents-cybersecurity-evals Socket
- irregular.com · next-generation-of-cyber-evals Socket
- cyberscoop.com · anthropic-claude-ai-hacks-real-companies Socket
- pypi.org Socket
- openai.com · hugging-face-model-evaluation-security-incident Socket
- bleepingcomputer.com · anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests Socket
- socket.dev · npm-rat-targets-alibaba Socket
- github.com · smi1e2u Socket
- socket.dev · joyfill-npm-beta-releases-compromised Socket
- socket.io Socket
- sonatype.com · flooding-dropper-hits-npm-with-850-malicious-packages Sonatype
- guide.sonatype.com · sonatype-research Sonatype
- opensourcemalware.com · bigops-backend Sonatype
- sonatype.com · mini-shai-hulud-npm-attack-more-than-2200-components-impacted Sonatype
- guide.sonatype.com · sonatype-2026-005579 Sonatype
- ox.security · a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable Sonatype
- research.jfrog.com · shai-hulud-is-back-august Sonatype
- snyk.io · why-we-rebuilt-evo-ai-model-risk-scoring Snyk
- gitlab.com · 10036 GitLab Security Releases
- gitlab.com · 3006 GitLab Security Releases
- gitlab.com · 244020 GitLab Security Releases
- gitlab.com · 244214 GitLab Security Releases
- gitlab.com · 244097 GitLab Security Releases