Ethical Hacking News
Hackers impersonate IT support to breach leading financial companies, stealing sensitive data and extorting ransoms from victims. The attackers' sophisticated tactics highlight the importance of robust security measures and employee education in preventing such breaches.
Hackers impersonate IT support to gain access to sensitive data from leading financial companies, tricking employees into divulging their login credentials. The hackers created fake websites that appeared legitimate, prompting victims to update passkeys or MFA using their personal phones. The attackers used automated tools to steal data from cloud services such as Microsoft 365 and Okta. The hackers targeted over 200 firms, including major financial companies, and demanded ransoms of $1 million to $3 million in exchange for not releasing the stolen data. The UNC6671 cybercrime group operates under several extortion brands and tracks its targets using voice phishing. Organizations must maintain robust security measures and educate their employees on these tactics to prevent such breaches.
Hackers have employed a devious tactic to gain access to sensitive data from leading financial companies, impersonating IT support and tricking employees into divulging their login credentials. According to recent reports, the hackers created fake websites that appeared legitimate, prompting victims to update passkeys or MFA (Multi-Factor Authentication) using their personal phones. These fake IT helpdesks utilized voice phishing, posing as the company's IT support team, creating a false sense of urgency and fear among employees.
The attackers employed sophisticated tactics, utilizing automated tools to steal data from cloud services such as Microsoft 365 and Okta. They also spoofed legitimate phone numbers, adding an air of legitimacy to their calls. This tactic allowed them to circumvent corporate security controls and gain access to sensitive information without being detected.
The hackers targeted over 200 firms, including major financial companies such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. In some cases, companies paid ransoms to the hackers, who typically demanded between $1 million and $3 million in exchange for not releasing the stolen data.
The hackers operated under several extortion brands, including Redact, Pink, Helix, and Falcon, but their attack methods and infrastructure remained largely unchanged. This suggests that the campaigns are closely linked and that the group's focus has shifted repeatedly, moving from other sectors into private equity, law firms, and financial ratings agencies, wherever the calculation suggests the data is worth enough to generate a payment.
The UNC6671 cybercrime group, which operates under several of these extortion brands, continues to track its targets using voice phishing. The group has also built digital traps for more than 200 companies in the past five weeks, including Uber, Zillow, Levi Strauss, and several law firms such as Paul Hastings and Greenberg Traurig.
The actual relationships between these groups remain unclear to investigators, though they appear to share common infrastructure. The campaign has been successful in breaching leading financial companies, highlighting the importance of robust security measures and employee education.
In another related development, Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. GTIG also identified 18 Bitcoin wallets linked to BlackFile between January and May 2026, which received 141.65 BTC worth about $10.69 million.
In conclusion, hackers have employed a sophisticated ploy to gain access to sensitive data from leading financial companies, impersonating IT support and tricking employees into divulging their login credentials. The attackers' tactics are clever, using voice phishing, automated tools, and fake websites to steal data from cloud services and other targets. It is essential for organizations to maintain robust security measures and educate their employees on these tactics to prevent such breaches.
Hackers impersonate IT support to breach leading financial companies, stealing sensitive data and extorting ransoms from victims. The attackers' sophisticated tactics highlight the importance of robust security measures and employee education in preventing such breaches.
Related Information:
https://www.ethicalhackingnews.com/articles/Hackers-Sophisticated-Ploy-Exploiting-Trust-to-Steal-from-Leading-Financial-Companies-ehn.shtml
https://securityaffairs.com/196800/security/hackers-impersonate-it-support-to-breach-leading-financial-companies.html
Published: Fri Aug 7 12:21:26 2026 by llama3.2 3B Q4_K_M