Hedge funds hit by vishing attacks: UNC6671 extortion group breached cloud systems

Hedge funds hit by vishing attacks: UNC6671 extortion group breached cloud systems

Google Threat Intelligence Group (GTIG) has linked a wave of cyberattacks on hedge funds and private-equity firms to UNC6671, an extortion group previously operating under the BlackFile brand. The attackers used voice phishing, or vishing, to trick employees into granting access to corporate systems.

According to Reuters and Bloomberg, the victims included Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms. Point72 told investors it had been attacked but found no evidence that client data was stolen. Two Sigma said it blocked an attempted intrusion and found no signs that its systems or data were affected. Millennium and Citadel declined to comment, while Point72 and Two Sigma did not respond to requests.

GTIG analyst Austin Larsen confirmed to BleepingComputer that the company tracks this activity as UNC6671. He said the group, previously publicly known as BlackFile, has expanded its extortion operations under multiple brands — Redact, Pink, Helix, and Falcon. GTIG assesses that a single core intrusion group is behind the helpdesk vishing and cloud data theft across these public brands.

BlackFile first emerged in February 2025, targeting retail and hospitality organizations. According to a Mandiant report, since July 2026 the group shifted its focus to private-equity firms, hedge funds, major law firms, and financial-rating agencies. Earlier targets included manufacturing, healthcare, real estate, technology, transportation, and hospitality sectors.

Larsen cited GTIG data showing that between January and May 2026, the group received over $10.6 million in Bitcoin payments. Initial demands reached up to $3 million, but after negotiations operators typically settled for around $750,000.

UNC6671 attacks focus on cloud environments. Operators call employees on personal mobile phones, posing as corporate helpdesk staff, and convince them to enroll passkeys or perform other actions that open access to systems.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate