Google's security researchers reported that several hacking groups are actively targeting major financial and investment firms in the United States. These groups employ a technique known as vishing, or voice phishing, to gain unauthorized access to company systems. The objective is to steal sensitive data and then extort the victims by threatening to publish the stolen information.
The hacking groups, which Google has named Falcon, Helix, Pink, and Redact, initiate phone calls to employees' personal cellphones. During these calls, the attackers impersonate co-workers or IT helpdesk staff. Their goal is to trick employees into entering their login credentials and multi-factor authentication codes onto spoofed websites, thereby compromising their accounts.
After successfully exfiltrating data, some of these groups operate websites where they publicize their breaches and issue threats to leak the stolen data. This tactic is a common cybercriminal strategy to pressure victims into paying a ransom. One such site stated, "The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement."
Google researchers suggest that these distinct hacking groups may be part of a larger, coordinated collective, which Google tracks as UNC6671. The researchers believe this structure, with multiple public extortion brands, could be an effort to compartmentalize operations, obscure the total volume of breaches, and isolate the fallout from any negotiation failures.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google security researchers identified multiple hacking groups using vishing (voice phishing) to compromise U.S. financial and investment firms, aiming to steal sensitive data for extortion. These groups, potentially part of a larger collective, trick employees into providing credentials and multi-factor codes over the phone, highlighting the continued effectiveness of social engineering tactics.