Private Equity Cybersecurity: Inside the UNC6671 Vishing Extortion Scheme

On August 6, 2026, Google Threat Intelligence Group released an analysis of UNC6671, a threat cluster associated with extortion campaigns that use help desk vishing against financial services, private equity, and professional services organizations.

The underlying technique is familiar. What has changed is the choice of targets.

Between April and July 2026, UNC6671 shifted from broad enterprise credential theft toward organizations holding sensitive M&A, capital deployment, and litigation information. The analysis below examines the attack chain and the controls capable of disrupting it. The activity follows the recent coordinated vishing campaign that affected Citadel, Two Sigma, Point72, and Millennium.

What is UNC6671 and which firms were targeted?

UNC6671 is the name used by Google Threat Intelligence Group for a threat cluster that has operated through five successive extortion brands. GTIG telemetry indicates that the operation did not cease when individual brands disappeared. Instead, it continued under BlackFile, Redact, Pink, Helix, and Falcon. Shared phishing templates, overlapping targeting patterns, and reused root domains connect these brands to the same broader operation.

Google did not publicly identify individual victims. Reuters later reported that the organizations targeted included Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. None of those firms has confirmed the report, while CME Group declined to comment. The victim list should therefore be treated as reported rather than independently verified. The attack methodology itself, however, is documented directly by Google.

How does the vishing attack chain work?

  1. Reconnaissance and infrastructure staging: The threat actor registers generic root domains built around enterprise authentication terminology. These domains combine words such as passkey, MFA, or SSO with an action-oriented term. Examples include passkeyhelpdesk[.]com and createssopasskey[.]com. A company-specific subdomain is then created so that the targeted employee sees the name of the organization in the URL.
  2. The call: An operator contacts the employee by phone, often through a personal mobile number that falls outside normal corporate security controls. In recent incidents, the threat actor also spoofed the organization’s legitimate help desk number. The caller presents the request as an urgent and mandatory security procedure, such as enabling FIDO2 passkeys or re-enrolling MFA.
  3. Credential and token capture: The caller directs the employee to the fraudulent company-specific subdomain. Adversary-in-the-middle infrastructure behind the page relays the authentication session in real time. This allows the operator to capture both the password and the corresponding MFA response.
  4. Persistence: Once a valid session has been obtained, the threat actor registers an additional MFA device under its control. Subsequent authentication is performed through residential proxy infrastructure selected to match the employee’s geographic location.
  5. Automated SaaS exfiltration: Automated scripts extract information directly from Microsoft 365 and Okta. Google observed scripting user agents such as python-requests and WindowsPowerShell generating high-volume file access.
  6. Extortion: The stolen information is either published or threatened with publication through a leak site associated with the actor’s current extortion brand.

What’s new?

Since the recent hedge fund vishing campaign, the attackers have introduced additional deception and defense-evasion techniques.

  • Spoofing the legitimate help desk number allows an incoming call to appear as if it originated from an authentic internal contact. This removes an important verification signal that employees might otherwise rely on.
  • UNC6671 has also made inbox manipulation a recurring part of its operations. After compromising an email account, the actor can initiate password resets for applications that are not connected to SSO. Reset confirmations, notifications about MFA changes, and security alerts are then deleted from the mailbox.
  • The use of five separate extortion identities creates another layer of concealment. Security reporting that treats each brand as an independent group can therefore significantly understate the overall scale of the same underlying operation.

Why are private equity and financial services firms the target?

Google’s domain-registration data indicates a deliberate evolution in the actor’s targeting strategy during 2026.

PeriodTarget profileApparent objective
April to May 2026Manufacturing, real estate, healthcare, insuranceLarge-scale credential harvesting across major enterprises
June 2026Technology, transportation, hospitalityIntellectual property, source code, and VIP client information
July 2026 onwardPrivate equity, law firms, financial rating agenciesM&A, capital deployment, and litigation information with high extortion value

The motivation is straightforward. Private equity organizations possess transaction-related information whose premature disclosure can create consequences well beyond the firm itself. That information can affect LP commitments, counterparty positions, regulatory exposure, and the terms of active transactions. This imbalance increases the leverage available to an extortionist and can support a larger ransom demand.

Google identified approximately one newly registered domain every 1.6 days during June and July. In April and May, the rate had been approximately one domain every 2.2 days. Seven domains were provisioned within a single 72-hour period in late July.

Google also tracked 18 BlackFile Bitcoin wallets between January and May 2026. Together, they received 141.65 BTC, worth approximately $10.69 million at the time of the transactions. Payments continued even after the May 11 shutdown announcement. This indicates that the operation did not actually stop during the subsequent rebranding.

Initial ransom demands generally fell between $1 million and $3 million. Negotiations often reduced the requested amount by 50% to 75%. In more than 53% of the cases tracked by Google, final payments averaged $750,000.

How do private equity firms defend against vishing?

A vishing call cannot normally be detected by an email security gateway or an EDR platform. Effective defenses therefore need to operate at the procedural, identity, and behavioral layers. The measures below provide a concise summary of the action items outlined in the CISO playbook on AI vishing attacks and finance-team defense.

Priority security measures

PriorityAction itemOwner
P0Require an out-of-band callback to a pre-registered number whenever a voice request involves credentials, access, or money movementIT help desk, treasury
P0Deploy phishing-resistant authenticators, including FIDO2 security keys, passkeys, and platform authenticators, across SSO and IdP environments. Origin binding prevents authentication through lookalike domainsIdentity, IT operations
P0Establish a standing policy requiring unsolicited calls to personal devices that claim to come from IT to be ignored and reportedSecurity, HR
P1Strengthen identity verification procedures for help desk MFA resets and new authenticator enrollmentIT operations
P1Conduct quarterly vishing simulations for deal teams, finance, treasury, executive assistants, and help desk personnelSecurity awareness
P1Configure alerts for new MFA device enrollment, anomalous session geolocation, and authentication through residential proxiesSecurity operations
P2Run a tabletop exercise covering a successful impersonation call, including a scenario involving synthetic mediaCISO, IR lead

Why technology only works in tandem with experience

  • Callback remains effective even when other verification signals fail. An attacker can spoof the help desk’s caller ID, imitate a person’s voice, and maintain a convincing conversation under time pressure. The same attacker cannot receive a verification call placed to the legitimate number already recorded by the organization.
  • Phishing-resistant MFA provides the corresponding technical safeguard. WebAuthn cryptographically binds an authenticator to the legitimate domain. As a result, authentication cannot be successfully completed through a fraudulent lookalike domain, even if the social-engineering call itself is convincing.
  • Both controls become less effective when employees have never encountered the underlying pretext. Recognition depends on prior exposure rather than on the existence of a written policy alone. Employees who have previously experienced a realistic simulated call are more likely to recognize the real technique quickly. More importantly, they are more likely to escalate the incident through the correct channels.

Conclusion

Google Threat Intelligence Group assesses UNC6671 as a coordinated threat cluster operating through five extortion brands: BlackFile, Redact, Pink, Helix, and Falcon. Its intrusion model is centered on identity rather than malware or zero-day exploitation. The core chain combines a phone call, a fraudulent passkey-enrollment portal, and adversary-in-the-middle infrastructure capable of capturing both credentials and MFA responses. Employees are frequently contacted through personal mobile numbers that sit outside corporate security visibility, while recent incidents have also involved spoofing of legitimate help desk numbers. By July 2026, targeting had shifted toward private equity firms, law firms, and financial rating agencies, with new infrastructure appearing at an average rate of roughly one domain every 1.6 days. Initial ransom demands typically ranged from $1 million to $3 million, while Google observed final settlements averaging $750,000 in more than half of the tracked cases. The two most effective controls for breaking this attack chain are phishing-resistant authentication and out-of-band callback procedures. Regular vishing simulations provide the practical preparation needed for those controls to remain effective when employees face a convincing real-world caller.

Arsen platform fortifies a critical vulnerability in any cybersecurity infrastructure: the workforce. The human element continues to be a primary risk, particularly as social engineering and artificial intelligence become more advanced.

Get Arsen Demo



    Subscribe to news