Protect.Computer
NEWS

Extortion Group UNC6671 Uses Vishing to Target Hedge Funds

· 1 min read · Got hacked Digital scams
Extortion Group UNC6671 Uses Vishing to Target Hedge Funds

A wave of cyberattacks against hedge funds, private-equity firms, and major law firms has been attributed to UNC6671, a threat group that Google’s Threat Intelligence Group (GTIG) says is the single core intrusion team behind several extortion brands: BlackFile, Redact, Pink, Helix, and Falcon. The attacks rely on voice phishing — attackers call employees and impersonate IT helpdesk staff or other internal personnel to talk them into handing over access credentials or approving remote-access sessions. Named targets include Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel, along with several private-equity firms. Point72 confirmed it was attacked but found no evidence that client data was stolen. Two Sigma said it blocked the intrusion attempt and saw no sign that systems or data were compromised. Millennium and Citadel declined to comment.

UNC6671 first appeared publicly as BlackFile in February 2025, initially targeting retail and hospitality companies in a wave of data-theft extortion attacks. Mandiant’s analysis shows the group pivoted in July 2026 toward financial firms — a sector with both deep pockets and highly sensitive data that commands premium ransom leverage. Google GTIG assessed that a single crew is running all of the extortion brands simultaneously, cycling through public-facing names to evade pattern recognition by defenders and journalists. The vishing technique itself is not new — it was the primary method used in the 2024 MGM Resorts breach — but the group has refined it for financial-services targets, where employees in trading and operations are trained to act quickly and are less likely to slow down for verification procedures. GTIG has tracked over $10 million in extortion payments attributed to this cluster.

Sources

Related reading