UPDATED 20:04 EDT / AUGUST 06 2026

SECURITY

Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew

Google LLC’s Threat Intelligence Group today said the extortion crew behind the retired BlackFile brand has spent June and July working its way through private equity firms, law firms and financial services companies.

Reuters reports that the phishing domains registered for the campaign name their intended victims. Blackstone Inc., KKR & Co. Inc., Apollo Global Management Inc. and CME Group Inc. all turn up in the set, alongside the law firms Paul Hastings LLP and Greenberg Traurig LLP. None of the firms has confirmed a breach, and Greenberg Traurig told Reuters none occurred

The group is tracked as UNC6671. Earlier in the year, its operators went after manufacturers, real estate firms, hospitals and insurers in bulk. Google’s analysts read the newer target list as a play for leverage, since a firm sitting on live merger documents or litigation files has more reason to pay quietly.

Four public extortion brands now sit on top of that single intrusion cluster, according to the report. Redact, Pink, Helix and Falcon share phishing infrastructure, and in several cases, identical phishing templates went live on the same day across domains claimed by different brands. BlackFile announced its retirement on May 11. Bitcoin payments to its wallets were still landing the next day. Redact surfaced on June 27 with a statement claiming the BlackFile name had been “compromised and hijacked by an exiled affiliate.”

Employees get a voice phishing call on their personal mobile phones. The number is spoofed to match the corporate IT help desk, and the caller says a FIDO2 passkey enrollment or a multifactor update has to be done that day. The link leads to a subdomain built to resemble the employer’s, one example being [company].createssopasskey[.]com. Behind it sits an adversary-in-the-middle proxy that harvests the password and the live session token together.

Once inside, the crew cleans up after itself. Password reset confirmations get deleted. So do the alerts that would otherwise tell colleagues someone had changed an MFA configuration. Data then leaves Microsoft 365 and Okta tenants through automated scripts, pulling files at volumes no human browsing session would produce. The user agents left behind in the logs include python-requests and Windows PowerShell.

Google linked 18 wallets to BlackFile and tracked about $10.7 million flowing into them between Jan. 7 and May 12. Demands typically started at $1 million to $3 million. Roughly half the negotiations Google followed ended near $750,000.

Domain registration has sped up. Google counted 28 phishing domains across April and May, about one every 2.2 days. Through June and July, the pace rose to one every 1.6 days.

The attempts on hedge funds surfaced on Aug. 5, when Bloomberg reported attempted intrusions at Point72 Asset Management LP, Citadel LLC, Millennium Management LLC and Two Sigma Investments LP. Point72 told investors it had seen no early sign that client information was taken. Two Sigma said its security team “responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers,” with no impact to its systems or data. The Financial Industry Regulatory Authority has since contacted member firms.

Jeremiah Fowler, a researcher at Black Hills Information Security Inc., said the economics explain the target list. “When the goal of cyber criminals is financial gain it is only logical that investment firms that manage sensitive financial information are attractive targets,” he said in comments circulated to reporters. Victim profiles that once took a skilled operator weeks to assemble can now be pulled together from breach data and public sources in minutes, he added.

Phil Wylie, senior consultant and evangelist at security solution provider Suzu Labs, said the fix is procedural. Verification steps that do not rely on an employee recognizing a familiar voice are what stop the call, he said, and the speed at which these attempts were spotted shows what firms get out of sharing intelligence with each other.

Google’s hardening advice leans on hardware. Roaming FIDO2 keys and platform authenticators such as Okta FastPass bind an authentication to its origin, which is what breaks the proxy trick. The rest of the list covers shorter sessions, daily reauthentication and blocking logins from unmanaged personal devices. Google also wants bulk “FileAccessed” events from scripting user agents treated with the same suspicion as an outright download.

Image: SiliconANGLE/GPT Image 2

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

Are you AWS customer?  Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.  

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.