Google warns Blackstone, Bridgewater, Bain, KKR, TPG, Moody’s of phone hack
Google has warned several major financial firms, including Blackstone and KKR, about a sophisticated vishing campaign by hackers known as UNC6671. The attackers use voice phishing to steal credentials and MFA tokens to exfiltrate data from cloud environments.
Why it matters
This highlights the persistent vulnerability of high-profile financial institutions to social engineering and credential theft.
Google has revealed that ransom-seeking hackers have targeted dozens of major US financial institutions and businesses in recent weeks, including Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG, and Moody’s. According to a report by Reuters, the attackers used phone calls to trick employees into revealing credentials, then deployed malicious websites tailored to each firm. “Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in