Google: Hackers Are Calling Employees to Extort Firms
08 Aug 2026
Google's security researchers published a report on Thursday detailing hacking groups that are targeting employees at large financial and investment firms in the United States through phone-based social engineering — essentially, calling employees directly to trick them into granting network access.
What happened
According to Reuters, victims identified in Google's report include private equity and asset management firms Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG. Google also notes the same hacking groups have previously targeted large companies outside finance, including in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality.
Google has named four distinct hacking groups — Falcon, Helix, Pink, and Redact — which it tracks collectively under the umbrella designation UNC6671. The company says it's unclear whether these groups are affiliates, splinter factions, or simply share the same Phishing-as-a-Service infrastructure. That overlapping infrastructure, Google notes, could make attribution and defense more difficult for targeted organizations.
The extortion playbook
The attackers' method follows a familiar but effective pattern: gain access via a phone call to an employee, exfiltrate sensitive company data, then threaten to leak it publicly unless a ransom is paid. Demands typically range from $750,000 to $3 million, according to the report. One cryptocurrency wallet tied to a single hacking group reportedly received $10 million in bitcoin in just the first few months of this year.
One group's extortion website reportedly framed the operation in businesslike terms: "We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement."
What we still don't know
Several important details remain unclear. Google's report doesn't specify how many victims actually paid ransoms or the total amount collected across all incidents. The precise mechanics of the phone-based social engineering — what pretexts callers used, which employees were targeted — aren't detailed either. The relationship between the four named groups and the UNC6671 umbrella is also unconfirmed, and none of the listed companies have publicly confirmed being victims or commented on the report. It's also not known what specific data was stolen or whether any has actually been published.
Why founders should care
This report likely signals that phone-based social engineering is becoming a more common vector against employees — not just at banks and PE firms, but potentially across any industry handling sensitive data. Founders at fintech and adjacent companies should probably treat this as a prompt to revisit employee security training, particularly around verifying identity on unsolicited calls before granting any system access.
The spread of past targets across manufacturing, healthcare, insurance, tech, and hospitality suggests no sector is clearly exempt, even if financial firms appear to be a current focus. And the scale of demands — up to $3 million per incident, with millions more flowing through associated crypto wallets — indicates that extortion-based attacks could represent a material and growing operational risk for companies that store sensitive financial or client data, regardless of size.
For early-stage founders, the practical takeaway is straightforward: identity verification protocols for employee-facing communications and basic social-engineering awareness training may be worth prioritizing now, before a single phone call turns into a seven-figure problem.