Voice Phishing Attacks Target Hedge Fund Employees
KnowBe4, Thursday, August 27th, 2026
KnowBe4 relays Google GTIG reporting on UNC6671 vishing campaigns against hedge funds to bypass MFA.
Google's Threat Intelligence Group is tracking a voice phishing campaign targeting hedge funds and financial firms, attributed to UNC6671, an extortion group formerly known as BlackFile.
The attackers call employees posing as IT staff and inform them of urgent, mandatory migrations, creating time pressure and a plausible reason to request cooperation.
The goal is bypassing multi-factor authentication and hijacking cloud accounts, using the victim to approve the authentication step the attacker cannot complete alone. Google GTIG warns that the financial sector is being targeted specifically.