Hackers Target Private Equity Firms with Voice Phishing Attacks

Cybercriminals have shifted their focus toward private equity firms and related financial organizations, employing voice phishing tactics to infiltrate systems and extract sensitive information for extortion purposes, according to findings from Google’s threat intelligence researchers. The activity stems from a cluster tracked as UNC6671.

Despite public claims that one associated extortion operation known as BlackFile had shut down in May 2026, analysis of infrastructure and telemetry shows the actors continued operations under multiple overlapping brands, including Redact, Pink, Helix, and Falcon.

These brands share consistent methods for initial access and data theft even as they maintain separate public-facing leak sites and negotiation channels.

Attackers primarily rely on carefully orchestrated phone calls directed at employees’ personal mobile numbers.

Posing as internal IT helpdesk personnel, they create a sense of urgency around mandatory security updates, such as enabling passkeys or revising multi-factor authentication settings.

In some instances, the callers spoof legitimate helpdesk numbers to enhance credibility.

Victims are then directed to convincing but fraudulent login pages designed to capture credentials and authentication tokens in real time through intermediary interception techniques.

Once access is obtained, the operators establish persistent sessions and use automated scripts to systematically extract data from cloud platforms, including Microsoft 365 and Okta environments.

They take additional steps to hide their presence by deleting confirmation messages, security alerts, and other notifications that might alert the legitimate account holders.

Researchers observed a clear evolution in targeting preferences. Earlier waves focused on broader enterprise sectors such as manufacturing, healthcare, and technology.

By mid-2026, attention narrowed toward financial services, private equity firms, law practices, and ratings agencies.

Organizations handling mergers, acquisitions, capital allocation, and litigation appear particularly attractive because the confidential data they hold can strengthen leverage during ransom negotiations.

Ransom demands commonly begin in the range of one to three million dollars. Negotiations frequently result in reduced payments, with final settlements averaging around $750,000 in many observed cases.

Blockchain analysis of wallets linked to the earlier BlackFile activity showed receipts exceeding ten million dollars in bitcoin over several months, with transactions continuing after the purported brand retirement.

The campaign underscores how social engineering can bypass sophisticated technical defenses by exploiting human trust and the accessibility of personal devices.

Private equity firms, which routinely manage highly sensitive deal information and client details, face elevated risk because successful breaches can yield particularly valuable data for extortion.

Defenders are advised to prioritize phishing-resistant authentication methods that bind credentials cryptographically to legitimate domains, tighten session management, restrict access to trusted networks, and monitor identity logs for anomalous patterns such as unexpected multi-factor enrollment attempts following failed authentications.

Integrating SaaS applications under centralized single sign-on controls and scrutinizing bulk data access from scripting tools can further reduce exposure.

As threat actors continue refining these human-centric approaches while rotating public brands, organizations in the investment and professional services sectors must treat voice-based social engineering as a primary risk vector rather than a secondary concern.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend