Hackers are calling Wall Street employees on their personal phones, and it’s working

One hacking group’s extortion site reads like a corporate press release. “We conduct every negotiation on professional terms,” it says. “Respond promptly and in good faith, and the matter is resolved without further incident.” Professional tone aside, the groups behind these messages have pulled in at least $10 million in bitcoin this year alone, and their targets include some of the biggest names in American finance.

According to TechCrunch, Google’s security researchers published a report identifying multiple hacking groups targeting large U.S. financial and investment firms. The goal is straightforward: steal sensitive data, then threaten to publish it unless the victim pays. Reuters identified some of the targets as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. None of those firms responded to requests for comment, which tells you something.

The technique the groups are using is not sophisticated in a technical sense. It’s voice phishing, or vishing. Hackers call employees on their personal cellphones, pretend to be coworkers or IT helpdesk staff, and trick them into entering credentials and multi-factor authentication codes on fake websites. No zero-day exploits. No nation-state malware. Just a phone call and a convincing story. And it keeps working, because humans are still the weakest point in any security setup, and multi-factor authentication is not the silver bullet the industry has been selling it as.

Google tracks the groups under the names Falcon, Helix, Pink, and Redact, and believes they may all fall under a larger collective the company calls UNC6671. Whether these are affiliates, splinter groups, or shared infrastructure customers isn’t clear yet. Google’s researchers suggest the multiple brands could be a deliberate strategy to hide total breach volumes and contain fallout from any single negotiation gone bad. That’s not amateur behavior. That’s operational security.

The broader picture here is worth paying attention to. These groups previously went after manufacturing, healthcare, real estate, insurance, tech, and hospitality companies. The recent shift toward private equity and legal firms makes strategic sense. Organizations involved in mergers, acquisitions, and litigation sit on exactly the kind of confidential data that creates maximum pressure during an extortion demand. The ransom range Google cites, $750,000 to $3 million per victim, reflects that calculation directly.

For employees at these firms, the practical takeaway is uncomfortable. Your personal phone number is findable. Caller ID is spoofable. And if someone calls claiming to be from IT and asking you to verify your login, that call may not be what it seems. The fact that these groups are bypassing corporate systems entirely and going straight to personal devices is a reminder that security awareness training needs to cover scenarios that most corporate IT departments still treat as edge cases.