Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies.A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens of other financial companies. In some cases, companies paid ransoms. Which ones, nobody is saying.“Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon.” reads the report published by Google. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations.”The attackers called employees on their personal phones while posing as the company’s IT help desk, sometimes spoofing the real support number. They created a false sense of urgency, directing victims to fake websites to update passkeys or MFA, where login credentials were stolen.If the employee followed the instructions and entered their password, the hackers harvested their second-factor passcode live over the phone and hijacked the account before the call ended. The attacker gets in, the phone call ends, and the employee has no idea anything happened. Attackers also hide their activity by deleting security alerts and password reset notifications from compromised accounts.“UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy.” continues the report. “During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain (e.g., [company].createssopasskey[.]com or [company].addssopasskey[.]com).”After gaining access, the attackers use automated tools to steal data from cloud services such as Microsoft 365 and Okta. Although the group has operated under several extortion brands, including Redact, Pink, Helix, and Falcon, its attack methods and infrastructure remain largely unchanged, suggesting the campaigns are closely linked.Threat actors selected targets based on their likelihood of paying to prevent the release of sensitive stolen data, making financial organizations particularly attractive victims.The UNC6671 cybercrime group has shifted its focus from large enterprises to higher-value targets, including private equity firms, law firms, and financial institutions. GTIG tracked 18 Bitcoin wallets linked to BlackFile between January and May 2026, which received 141.65 BTC worth about $10.69 million. Payments continued even after the group announced the shutdown of its leak site, showing that its operations remained active during the rebranding phase. The attackers typically demanded between $1 million and $3 million in ransom, but often negotiated discounts of 50–75%. In more than half of the tracked cases, victims paid an average ransom of around $750,000.“Notably, ransom payments to these wallets continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026. Multiple significant cashout events observed in late April and early May confirm that financial operations proceeded without interruption during the rebranding phase.” concludes the report.While Google did not identify any of the hackers’ victims by name, Reuters reverse-engineered many of the company-specific traps by running the 72 malicious websites Google listed in its report through web intelligence platforms DomainTools and urlscan, which flagged malicious subdomains tailored to each firm. Google said all were likely used in attempted intrusions, though not all were successful.The data shows the hackers built digital traps for more than 200 companies in the past five weeks, including Uber, Zillow, Levi Strauss, and several law firms including Paul Hastings and Greenberg Traurig. Point72 Asset Management told investors it had been targeted, and sources told Reuters the hackers also attempted to breach Two Sigma Investments and Citadel. Greenberg Traurig said it didn’t suffer a data breach due to its security protocols. Most other named firms declined to comment or didn’t respond.Redact, one of the group names, stated on its darknet site that its hackers “are not politically or morally motivated”, which at least has the virtue of being honest about the business model. Falcon acknowledged an affiliation with Redact but denied any connection to Helix or Pink. The actual relationships between these groups remain unclear to investigators, though they appear to share common infrastructure. The campaign has shifted focus repeatedly, moving from other sectors into private equity, law firms, and financial ratings agencies, wherever the calculation suggests the data is worth enough to generate a payment.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, financial companies)