One Extortion Group Hit Point72, Millennium, Two Sigma, and Citadel With the Same Phone Call Script
Cybersecurity

One Extortion Group Hit Point72, Millennium, Two Sigma, and Citadel With the Same Phone Call Script

Google's Threat Intelligence Group traced a wave of attacks on major hedge funds and private equity firms to UNC6671, a vishing-driven extortion group that has already collected over 10 million dollars in bitcoin this year.

PublishedAugust 10, 2026
Read time6 min read
Share

Who got hit and how bad it was

A wave of cyberattacks in mid-2026 targeted some of the largest names in finance: Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms whose identities have not all been publicly disclosed. Point72 confirmed it was attacked but reported finding no evidence that client data was stolen from its systems. Two Sigma said it detected and blocked an intrusion attempt before any systems or data were compromised, an outcome that reflects well on its detection capability given how effective this particular technique has proven against other well-resourced targets in the same period.

The consistency across targets, all large, sophisticated financial institutions with presumably mature security programs and substantial security budgets, is itself notable and worth sitting with. This was not a campaign that succeeded only against under-resourced victims with thin security teams. It succeeded, at least to the point of gaining initial access, against firms that run some of the most well-funded security operations in the private sector, which says considerably more about the attack technique itself than it does about any particular firm's defensive posture or investment level.

The technique: phone calls, not exploits

Google's Threat Intelligence Group and Mandiant identified the actor behind these intrusions as UNC6671, an extortion group whose method centers entirely on voice phishing rather than software exploitation or malware delivery. Attackers call employees directly, often from personal mobile phones specifically chosen to avoid corporate caller-ID filtering and spam detection, and impersonate the internal IT helpdesk with a confident, well-rehearsed script. The pretext is almost always the same regardless of victim: the employee needs to update their multi-factor authentication or enroll in a new passkey immediately, framed as routine, time-sensitive IT maintenance.

Employees who comply are directed to a phishing site that captures credentials and session cookies in real time as they are entered. From there, attackers gain access to the victim's Microsoft 365 or Okta single sign-on account, which in most modern enterprises functions as the master key to every connected cloud platform, from email and file storage to internal applications, HR systems, and, in a financial services context specifically, potentially trading platforms and portfolio management systems as well, depending on how broadly SSO has been federated across the organization.

The extortion economics behind the campaign

Google's GTIG tracked over 10.6 million dollars in bitcoin payments to the group between January and May 2026 alone. Initial ransom demands reportedly reached as high as 3 million dollars per victim, but the group typically settled closer to 750,000 dollars, a pricing pattern that suggests a deliberate negotiation strategy rather than opportunistic extortion. Austin Larsen, principal threat analyst at Google's GTIG, noted that 'UNC6671 has diversified its extortion operations across multiple public brands.'

That branding strategy is worth understanding on its own terms. The group first emerged as BlackFile in February 2025 targeting retail and hospitality sectors, then rebranded as Redact in May 2026, and currently runs at least three additional public-facing extortion identities: Falcon, Helix, and Pink. Operating under multiple names complicates victim attribution, muddies public reporting, and lets the group keep working even after any single brand draws sustained law enforcement or media attention.

Why vishing beats technical controls that took years to build

Financial services firms have spent the past decade hardening their technical perimeters: network segmentation, endpoint detection and response, hardware security keys, and increasingly sophisticated SSO deployments layered with conditional access policies. Vishing routes around nearly all of that investment by targeting the one control point that still depends entirely on human judgment in the moment, the employee deciding, under mild time pressure, whether a phone call claiming to be internal IT support is legitimate. No firewall rule or endpoint agent evaluates a phone conversation, and that gap is exactly what this campaign is built to exploit at scale.

The specific targeting of MFA reset and passkey enrollment flows is the technically sharp part of this campaign. Rather than trying to steal an existing credential, which modern hardware security keys make extremely difficult, the group manipulates victims into creating a brand-new authentication factor that the attacker controls from the start. That sidesteps phishing-resistant MFA entirely, because the attacker is not intercepting the strong factor, they are getting the victim to willingly issue them a new one.

Why a rebranding extortion group is harder to defend against

Security teams often build detection rules and threat intelligence subscriptions around named actor groups, which works well when an actor's identity stays stable over time. UNC6671's willingness to operate under five or more public brand names simultaneously, BlackFile, Redact, Falcon, Helix, and Pink, breaks that model in a specific and deliberate way. A threat intelligence feed tuned to flag chatter about 'BlackFile' will miss the exact same operators posting under 'Falcon' the following month, even though the tooling, infrastructure, and vishing scripts remain largely unchanged between identities.

This is a broader trend across the extortion ecosystem in 2026, not unique to this one group. Ransomware-as-a-service and extortion operations increasingly treat brand names as disposable marketing rather than fixed identity, cycling through new names to shed reputational baggage, dodge sanctions lists, or simply create confusion in public reporting. Defenders who anchor their threat models to named groups rather than to techniques, in this case helpdesk impersonation targeting authentication enrollment, will always be a step behind an adversary that treats its own name as replaceable.

What financial services and adjacent enterprises should do now

Any organization running Microsoft 365 or Okta SSO, which is nearly every large enterprise regardless of industry, should treat helpdesk-initiated MFA and passkey enrollment as a high-risk action requiring out-of-band verification, not a routine support ticket handled entirely over the phone. That means callback to a known employee number pulled from an internal directory rather than one provided by the caller, verification through a separate channel the caller did not initiate, or mandatory in-person verification for particularly sensitive roles like trading desk staff, finance, or executives with broad system access across the organization.

Point72 and Two Sigma's outcomes show the difference detection speed makes. Both firms report no confirmed compromise of client data or core systems despite being targeted by the same actor using the same technique that succeeded elsewhere. That gap between targeted and compromised is where security investment actually pays off for this specific threat: not in stopping the phone call from happening, which is nearly impossible to prevent entirely, but in detecting and containing the account takeover attempt within minutes of it occurring.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#unc6671#vishing#hedge-funds#point72#millennium-management#two-sigma#citadel#extortion#sso-security#financial-services