Some of the most sophisticated firms in finance are being hunted with one of the oldest tricks going: a phone call. A voice-phishing campaign has swept through a roster of Wall Street’s biggest names, and the target list reads like a finance directory.
It takes in the private-equity giants Blackstone, KKR and Apollo, the exchange operator CME, and hedge funds such as Point72, Citadel, Millennium and Two Sigma.
Law firms were in the crosshairs too, with Paul Hastings and Greenberg Traurig, both of which handle sensitive deal and litigation work, caught up in the same sweep.
The method itself is deceptively low-tech. Attackers call employees’ personal mobiles, spoofing numbers to impersonate corporate IT, and insist that an urgent passkey or multifactor-authentication update has to be completed that day.
The trap waiting at the end of the call is a fake login page: victims are steered to lookalike domains, where an adversary-in-the-middle proxy quietly harvests their passwords and session tokens as they type.
Those session tokens are the real prize, because stealing one lets an attacker slip past multifactor authentication entirely and log in as the victim without ever needing the second factor.
Researchers have a name for the crew doing this. Google’s threat analysts track it as UNC6671, an outfit that has operated under a rotating set of extortion brands to muddy attribution.
It is a rebrand as much as a group: linked to the retired BlackFile operation, it now runs under labels like Redact, Pink and Helix, which is a familiar way of staying a step ahead of defenders.
The campaign was industrial in tempo, running through June and July while the attackers registered new phishing domains at an accelerating clip to widen the net.
Even so, no breaches have been confirmed. Greenberg Traurig explicitly denied any breach, and firms including Point72 and Two Sigma said they detected no signs of data theft.
That is a useful reminder that being targeted is not the same as being compromised, since a determined campaign against dozens of firms can still be repelled, and the finance sector’s heavy security spending appears to have blunted this one so far.
The economics explain why the crew keeps at it. Google tracked millions of dollars flowing to the group’s wallets earlier in the year, with ransom demands that start high and settle in the hundreds of thousands.
That kind of payday sits behind a broader shift toward the human layer: as technical defences harden, attackers increasingly go after people, which is why identity and social engineering has become the hottest corner of cybersecurity.
The stakes only rise as data concentrates. Extortion crews have shown they will dump what they steal, as they did when ShinyHunters published 45GB of Madison Square Garden data, and finance firms hold far more sensitive material than most.
That is what makes the sector such an obvious target: these firms move enormous sums and sit on confidential deal and client data, so a single compromised login can be worth far more than in most industries.
The playbook also echoes other recent crews. Groups like Scattered Spider have shown how effective slick, English-language social engineering can be against big companies, and UNC6671 is working the same seam.
The defence is shifting accordingly, with firms moving toward phishing-resistant hardware keys and stricter verification for IT requests, both designed to make a convincing phone call far less useful to an attacker.
Regulators are watching too, since financial firms face tightening disclosure rules around cyber incidents, which means even an attempted campaign on this scale draws scrutiny from supervisors as well as security teams.
For Wall Street, the lesson is an uncomfortable one, and it is not a new one either. The weak point is not the firewall but the phone, and defending it means training people as carefully as configuring machines, because the most convincing attack still arrives as a friendly voice asking for a moment of trust.
Get the TNW newsletter
Get the most important tech news in your inbox each week.