A Phone Call Is All It Takes to Hack Wall Street’s Biggest Firms

Google’s Threat Intelligence Group tied UNC6671 to 10 major finance and law firms, with ransoms averaging $750,000 per victim

Alex Barrientos Avatar
Alex Barrientos Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • UNC6671 bypassed multifactor authentication by stealing session tokens via fake IT phone calls.
  • Attackers targeted Blackstone, KKR, Citadel, and other Wall Street giants in a coordinated vishing campaign.
  • Adopt FIDO2 hardware keys and call-back protocols to close gaps UNC6671 actively exploits.

Your phone buzzes on a Tuesday afternoon. The voice on the other end sounds like corporate IT — polite, professional, urgent: your multifactor authentication needs an update today, and here’s the link. That script, not a zero-day exploit or nation-state malware, is what attackers used to target Blackstone, KKR, Citadel, Apollo, and a roster of Wall Street’s most fortified institutions through June and July 2026. Google’s Threat Intelligence Group identified the group as UNC6671 and published its findings in early August. The weapon of choice was a phone call.

How a Phone Call Beats a Firewall

Attackers skipped the technical defenses entirely by stealing session tokens through fake IT calls to personal mobiles.

The assumption used to be that multifactor authentication was the lock on the vault. UNC6671 didn’t bother picking it. Callers impersonated IT help desks and directed employees to lookalike login pages. Adversary-in-the-middle proxies then captured credentials and session tokens at the same moment. Session tokens are the digital proof that you already passed MFA — steal one, and the second factor becomes decoration.

  • Calls targeted employees’ personal phones, not corporate lines
  • Named targets included Blackstone, KKR, Apollo Global Management, CME Group, Point72, Citadel, Millennium, Two Sigma, Paul Hastings, and Greenberg Traurig
  • Google linked UNC6671 to the retired BlackFile operation, now cycling through extortion brands called Redact, Pink, and Helix
  • Between January and May 2026, Google tracked roughly $10.69 million flowing through 18 BlackFile Bitcoin wallets; while initial ransom demands ran into the millions, final payments averaged around $750,000
  • Point72, Two Sigma, and Greenberg Traurig all reported no signs of data theft — being targeted is not the same as being breached

Google’s analysts described the campaign as a coordinated, industrial-scale vishing effort — not random spam calls from a boiler room.

Why the Smartest Firms Keep Falling for It

Technical defenses keep hardening, so attackers pivot to the one vulnerability that never gets patched — human trust.

This playbook echoes Scattered Spider’s earlier campaigns: English-speaking callers, help-desk impersonation, urgency that short-circuits skepticism. Like those viral deepfake audio clips that fooled executives into wiring funds, a convincing voice overrides rational judgment faster than any malware payload. The firms holding the most sensitive deal and client data become the most valuable targets precisely because their information commands the highest ransom.

The defensive response is shifting toward:

  • Phishing-resistant hardware keys built on the FIDO2 standard
  • Stricter out-of-band verification for IT requests
  • Mandatory call-back protocols

If your company’s help desk can reach your personal phone and ask you to click a link — without a separate verification step — that gap is exactly what UNC6671 exploits. A good rule: treat any unsolicited IT call requesting authentication changes as suspicious until you can confirm it through an independent channel your organization controls.

The most sophisticated financial infrastructure on the planet remains vulnerable to an attack that requires zero lines of code — just confidence and a spoofed caller ID.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →