Major Wall Street firms, hedge funds, and private-equity organizations were targeted in a recent wave of attempted cyberattacks that used phone-based social engineering to gain access to corporate systems. Reported targets included Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel; Point72 said it found no evidence that client data was stolen, while Two Sigma said it blocked an attempted intrusion with no sign of impact. Reuters and Bloomberg also reported that several private-equity firms were targeted in the same campaign.
Researchers attributed the activity to UNC6671, an extortion group previously associated with the public brand BlackFile and now linked to brands including Redact, Pink, Helix, and Falcon. According to Google Threat Intelligence Group and Mandiant, the attackers used help-desk voice phishing to persuade employees to change passkeys or MFA settings, then redirected victims to adversary-in-the-middle phishing pages that captured Microsoft 365 or Okta credentials and session cookies. Investigators said the group shifted in July toward hedge funds, private-equity firms, major law firms, and financial-rating agencies, and tracked more than $10.6 million in Bitcoin payments to wallets tied to the operation between January and May 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Reuters reported that financially motivated attackers used vishing calls and 72 phishing sites impersonating corporate IT help desks to target more than 200 companies over the prior five weeks. Named targets spanned private equity, hedge funds, exchanges, ratings firms, law firms, and other major companies including Blackstone, KKR, CME Group, Moody’s, Citadel, Uber, Zillow, Levi Strauss, Paul Hastings, and Greenberg Traurig.
Mandiant reported that in July 2026 the group shifted its targeting toward private-equity firms, hedge funds, major law firms, and financial-rating agencies.
Google Threat Intelligence Group said it tracked more than $10.6 million in Bitcoin payments to wallets linked to UNC6671, illustrating the scale of the group's extortion activity.
Google reported that BlackFile conducted a wave of attacks against retail and hospitality organizations after emerging in February 2025.
Google said the group later tracked as UNC6671 first emerged publicly under the BlackFile brand as a data-theft extortion operation.
Google Threat Intelligence Group linked the recent wave of attacks on hedge funds, private-equity firms, and other financial organizations to UNC6671, a group it says previously operated as BlackFile and now uses multiple extortion brands.
Two Sigma Investments said it blocked an attempted intrusion and found no indication that its systems or data were affected.
Point72 Asset Management told investors it had faced an attack and said it found no evidence that client or customer information was stolen.
In recent days, hackers attempted a series of sophisticated intrusions against major Wall Street financial firms and money managers using phone-based social engineering to gain access or elicit sensitive information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcebleepingcomputer.com
Open sourceteiss.co.uk
Open sourcebloomberg.com
Open sourcereuters.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.