Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog

Stopping the IT Call Hitting Hedge Funds and Wall Street Firms

AUGUST 19, 2026
Marshall BennettMarshall Bennett
Chat with a real person
Stopping the IT Call Hitting Hedge Funds and Wall Street Firms

Key takeaways

  • Reporting from BleepingComputer and Security Boulevard tied vishing attacks on Point72, Citadel, and Two Sigma to UNC6671, a group researchers have tracked since January 2026 as it expanded from manufacturing, healthcare, and real estate into asset managers, private equity firms, and law firms by July.
  • Researchers say the attackers pose as IT helpdesk staff and pressure employees with an urgent 'security migration,' then send them to an adversary-in-the-middle login page that captures usernames, passwords, and MFA codes to access Microsoft 365 or Okta and connected cloud apps.
  • Threat intelligence cited by BleepingComputer says more than $10.6 million in Bitcoin went to the group’s wallets between January and May 2026; opening ransom demands often reach $3 million, with many settlements around $750,000.
  • The group originally operated as BlackFile before retiring that brand in May 2026 after law-enforcement attention, and researchers believe the same core team now uses names including Redact, Pink, Helix, and Falcon to compartmentalize operations and obscure total breach volume.
  • The article says the strongest technical defense is phishing-resistant MFA, which CISA calls the gold standard: FIDO2 security keys, passkeys, and device authenticators bind logins cryptographically to the real company domain, so fake login pages cannot relay or steal usable credentials.
  • Recommended priorities for security teams are to roll out phishing-resistant MFA first for finance, executive, and IT admin accounts, enforce a rule that IT will never ask for account verification through an unsolicited call to a personal phone, simulate this exact vishing scenario in training, and monitor for bursts of automated data access immediately after login.

An employee’s personal phone rings. The caller says they're from IT. There’s an urgent security migration happening, and it needs a quick verification before the deadline. No malware. No exploit. Just a voice, a sense of urgency, and a login page that looks exactly right.Arun Vishwanath, author of The Weakest Link and a former Harvard researcher on human cyber risk, has spent years studying why these calls work. “Social engineering attacks work because they compress cognition,” he wrote this year, leaving little time to notice, question, or get suspicious before acting.

Reporting from BleepingComputer and Security Boulevard has linked that call to attacks on Point72, Citadel, Two Sigma, and a growing list of hedge funds, private equity firms, and other financial institutions this year. Security researchers, whose work does not name individual victims, have tracked the group behind it since January 2026, under a name that keeps changing: UNC6671.

The approach is consistent across cases, according to research cited by both The Hacker News and BleepingComputer this August: the group poses as IT helpdesk staff and invents a mandatory, urgent security migration to pressure employees into acting fast. The tactic has been around for years. What has changed is how consistently it works, and how far it has traveled across industries in a single year.

A Campaign With a Pattern

UNC6671 first showed up targeting manufacturing, healthcare, and real estate companies in the spring. By June, it had moved into technology, transportation, and hospitality. By July, it was inside asset managers, private equity firms, and law firms. That progression matters more than any single breach. It shows a group testing an approach, refining it, and moving toward higher value targets once it was confident the approach held up.

The group’s original brand was BlackFile, retired in May 2026 after law enforcement attention. Researchers tracking the group assess that the same core team now operates under several names at once, including Redact, Pink, Helix, and Falcon, likely to compartmentalize operations, obscure the true breach volume, and keep any single brand’s negotiation troubles from touching the others. Retiring one brand and starting another is a business decision, made by people running this like a business.

The money reflects that. More than $10.6 million in Bitcoin moved to the group’s wallets between January and May 2026, according to threat intelligence cited by BleepingComputer. Opening demands often reach $3 million. Most settle around $750,000, a negotiated discount that shows up again and again across cases.

Why the Trick Works

Eleanor Watson, an IEEE member who researches AI ethics at Singularity University, has been tracking how this kind of manipulation is evolving. “AI transforms social engineering from crafted campaigns to dynamically optimized psychological operations,” she said this year. A vishing call built around urgency and a trusted job title is a simple, effective version of that idea already at work. Help desks are built to solve problems fast, and a caller who sounds convincing enough benefits directly from that design.

Here is the mechanism in full. A caller reaches an employee on a personal phone, outside normal monitored channels. They claim to be internal IT, resolving an urgent issue. The employee is guided to a login page that looks identical to the genuine one, an adversary in the middle setup that captures username, password, and multi factor code the moment they're entered. Those credentials open the door to Microsoft 365 or Okta, and single sign-on often extends that access to many of the organization’s other connected cloud applications. Automated scripts then move quickly, pulling data and deleting security alerts before anyone notices. Only after that does the extortion demand arrive.

Every one of those later steps depends on the first one working. A person has to be convinced, once, on a phone call. That is also the point where this is easiest to stop.

The Fix Already Exists

There is already a clear answer to this exact attack, and it matches how the technology works under the hood. The Cybersecurity and Infrastructure Security Agency (CISA) calls phishing-resistant multi factor authentication the gold standard for MFA. This type of MFA comes as FIDO2 security keys, passkeys, and built-in device authenticators. Here is why it works: each login gets tied cryptographically to the legitimate company domain. A fake login page can look exactly right to a person and still fail, because it cannot copy that cryptographic link. As Adaptive Security has explained it, the authenticator refuses to respond. Nothing exists for the attacker to relay, replay, or steal.

This kind of authentication shuts the door this campaign has been using to break in. It works even better alongside one more simple habit: treat any request to set up a new authenticator or reset account access, even a request that comes through the normal help desk process, with the same level of scrutiny as a wire transfer. Strong authentication blocks a fake login page. A verification habit blocks someone from talking their way past the help desk that controls it.

There is more encouraging news here. A separate vishing operation nicknamed Kratos, responsible for roughly 15,000 calls a month at its peak, has already been dismantled by law enforcement. BlackFile, the original brand behind this entire campaign, is confirmed shut down. Naming these groups publicly and disrupting their infrastructure is working, even as new brand names appear behind the same operators.

What This Means for Security Teams

This is a matter of prioritizing what already works and building one habit into daily practice.

  • Start with the accounts that matter most. Finance, executive, and IT admin logins should move to phishing-resistant multi factor authentication first, since those are the accounts this group has consistently pursued.
  • Give employees one clear rule they can act on without hesitation. IT will never ask someone to verify or migrate an account through an unsolicited call to a personal phone. Any request like that gets confirmed through a separate, known channel before anyone clicks anything.
  • Practice the specific scenario attackers are already using. Employees who have experienced a simulated version of this exact call, complete with the invented urgency and the fake login page, recognize the live version faster than employees who have only seen a sample phishing email.
  • Watch the moment right after login. A burst of automated data access following a normal looking sign in is one of the clearest signals available, and catching it automatically stops the theft while it is happening.

A Job Two Sides Can Share

Vishing works because it borrows something valuable: the trust built into a normal workday. Ariel Parnes, chief operating officer at the cloud security firm Mitiga and a former colonel in the Israeli military's cyber unit, sees that as the defining shift in how breaches happen now. "The most successful breaches in 2026 will exploit trust, not vulnerabilities," he said this year. A known fix already exists, and law enforcement has already disrupted part of this exact network. What remains is adoption, prioritization, and giving employees one habit that holds up under a convincing phone call.

Adaptive Security builds tools for exactly that kind of preparation, running realistic voice and SMS based simulations so a team's first encounter with this tactic happens safely in training, well before a live call from someone pretending to be IT ever arrives.

Get started with Adaptive Security

Get started

Human security for the AI era.