{
  "id": 243668,
  "title": "Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew",
  "url": "https://urgent.news/2026/08/07/blackstone-kkr-and-cme-targeted-in-vishing-wave-tied-to-blackfile-crew",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-07T00:04:49.000Z",
  "source": {
    "name": "SiliconANGLE",
    "slug": "siliconangle",
    "url": "https://siliconangle.com/2026/08/06/blackstone-kkr-cme-targeted-vishing-wave-tied-blackfile-crew/"
  },
  "original_language": "en",
  "account": "Cybercriminals, operating under the BlackFile brand, have been targeting private equity firms, law firms, and financial services companies with vishing attacks in June and July. The group, identified as UNC6671, also attempted intrusions at hedge funds Point72 Asset Management LP, Citadel LLC, Millennium Management LLC, and Two Sigma Investments LP. The extortion crew uses voice phishing calls, where spoofed numbers mimic corporate IT help desks, to demand FIDO2 passkey enrollment or multifactor updates. Upon compliance, phishing links lead to subdomains resembling the employer's website, harvesting passwords and session tokens. Once inside, the crew deletes password reset confirmations and MFA configuration alerts, then exfiltrates data through automated scripts. Google identified 18 wallets linked to BlackFile, with $10.7 million flowing into them from January to May. Demands ranged from $1 million to $3 million, with negotiations typically ending near $750,000. The surge in phishing domain registrations accelerated in April and May, with one domain appearing every 1.6 days. The Financial Industry Regulatory Authority has contacted member firms regarding the threat. Security experts advise verifying calls using hardware-based solutions like FIDO2 keys, daily reauthentication, and blocking logins from unmanaged devices.",
  "summary": "Google's Threat Intelligence Group has reported that a hacking crew, previously known as BlackFile, has been targeting private equity firms, law firms, and financial services companies in June and July. The group used vishing, or voice phishing, tactics to compromise their victims.\n\nThe hacking campaign involved creating websites aimed at stealing passwords from employees of several prominent companies, including Blackstone, KKR, Apollo Global Management, Bain Capital, TPG, CME Group, and Moody's. According to Google, some companies paid ransoms to the hackers.\n\nThe hackers, who operate under various names including Redact, Pink, Falcon, and Helix, used low-tech tactics such as phone calls to target the financial industry. Experts note that despite sophisticated security programs, traditional tactics can still be effective.",
  "key_points": [
    "BlackFile cybercriminals targeted Blackstone, KKR, and CME in vishing attacks.",
    "UNC6671 group used voice phishing calls to demand FIDO2 passkey enrollment.",
    "Google identified 18 wallets linked to BlackFile, with $10.7 million in transactions."
  ],
  "editors_take": "The targeted attacks on major financial firms and private equity companies by the BlackFile crew signal a widening of cybercrime tactics to exploit vulnerabilities in corporate security protocols.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}