Your phone buzzes on a Tuesday afternoon. The voice on the other end sounds like corporate IT — polite, professional, urgent: your multifactor authentication needs an update today, and here’s the link. That script, not a zero-day exploit or nation-state malware, is what attackers used to target Blackstone, KKR, Citadel, Apollo, and a roster of Wall Street’s most fortified institutions through June and July 2026. Google’s Threat Intelligence Group identified the group as UNC6671 and published its findings in early August. The weapon of choice was a phone call.
How a Phone Call Beats a Firewall
Attackers skipped the technical defenses entirely by stealing session tokens through fake IT calls to personal mobiles.
The assumption used to be that multifactor authentication was the lock on the vault. UNC6671 didn’t bother picking it. Callers impersonated IT help desks and directed employees to lookalike login pages. Adversary-in-the-middle proxies then captured credentials and session tokens at the same moment. Session tokens are the digital proof that you already passed MFA — steal one, and the second factor becomes decoration.
- Calls targeted employees’ personal phones, not corporate lines
- Named targets included Blackstone, KKR, Apollo Global Management, CME Group, Point72, Citadel, Millennium, Two Sigma, Paul Hastings, and Greenberg Traurig
- Google linked UNC6671 to the retired BlackFile operation, now cycling through extortion brands called Redact, Pink, and Helix
- Between January and May 2026, Google tracked roughly $10.69 million flowing through 18 BlackFile Bitcoin wallets; while initial ransom demands ran into the millions, final payments averaged around $750,000
- Point72, Two Sigma, and Greenberg Traurig all reported no signs of data theft — being targeted is not the same as being breached
Google’s analysts described the campaign as a coordinated, industrial-scale vishing effort — not random spam calls from a boiler room.
Why the Smartest Firms Keep Falling for It
Technical defenses keep hardening, so attackers pivot to the one vulnerability that never gets patched — human trust.
This playbook echoes Scattered Spider’s earlier campaigns: English-speaking callers, help-desk impersonation, urgency that short-circuits skepticism. Like those viral deepfake audio clips that fooled executives into wiring funds, a convincing voice overrides rational judgment faster than any malware payload. The firms holding the most sensitive deal and client data become the most valuable targets precisely because their information commands the highest ransom.
The defensive response is shifting toward:
- Phishing-resistant hardware keys built on the FIDO2 standard
- Stricter out-of-band verification for IT requests
- Mandatory call-back protocols
If your company’s help desk can reach your personal phone and ask you to click a link — without a separate verification step — that gap is exactly what UNC6671 exploits. A good rule: treat any unsolicited IT call requesting authentication changes as suspicious until you can confirm it through an independent channel your organization controls.
The most sophisticated financial infrastructure on the planet remains vulnerable to an attack that requires zero lines of code — just confidence and a spoofed caller ID.






























