Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire
BlackFile (now known as Redact) has been busy, raking in more than $10 milllion since the start of the year.
A sophisticated vishing campaign has targeted top US hedge funds and law firms, including Blackstone, KKR, and CME Group, among others. The criminal group, previously known as BlackFile and now called Redact, impersonates IT staff over the phone and guides victims to fake login pages to steal their credentials and authentication tokens.
Once inside the victim's accounts, the attackers access enterprise SaaS environments and exfiltrate sensitive data. The group then contacts the victims, threatening to leak their stolen information unless a ransom is paid. Google's Threat Intelligence team tracked $10.7 million flowing into 18 crypto wallets between January and May 2026, linked to the group's activities.
The group has shown remarkable success, registering a new phishing domain approximately every 1.6 days between June and July. Despite these incidents, none of the confirmed targets, such as Greenberg Traurig LLP, claimed to have been breached.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.