What the callers actually did
Google's own threat intelligence team identified a voice-phishing, or vishing, campaign run by four related groups it tracks under the names Falcon, Helix, Pink and Redact, which Google believes may operate under a single umbrella collective it labels UNC6671. The findings were reported by TechCrunch on 6 August 2026.
The method was direct and low-tech at its core: attackers called employees on their personal cellphones, not their work lines, and impersonated either a colleague or a member of the internal IT help desk. Victims were talked through to a website built to closely mimic their employer's real login portal, where they entered their username, password and the code from their multi-factor authentication app.
That last step is the one that matters. The fake site relayed the credential and the MFA code to the attacker in real time, so the attacker could log in to the real system within the same window the code was still valid - a technique known as a real-time MFA relay, or phishing-in-the-middle. The campaign ran through the first few months of 2026. Wallets linked to the groups received roughly 10 million dollars in bitcoin over that period, and compromises were typically followed by an extortion demand of between 750,000 and 3 million dollars.
Why private equity, not a retailer with a database
The organizations named in the reporting are Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG. That is not a random sample of large companies. It is a list of major US financial and private-equity firms, chosen with a specific logic that is worth stating plainly.
Most breach coverage assumes attackers want volume: a database of millions of consumer records to sell or ransom. Private equity and asset management firms hold comparatively little of that. What they hold instead is concentrated authority - a small number of employees, often a handful per firm, who can approve a wire, sign off on a transaction or move a material sum of money without a second signature. That concentration is the asset the attackers were actually after.
This is a different target-selection logic than the one most security coverage assumes, and it is the reason a phone call, not a phishing email blasted to thousands of inboxes, was the right tool for the job. You do not need to compromise a database when compromising three or four specific people gets you the same result faster and with less noise.
Why the call beat your entire security stack
Multi-factor authentication, single sign-on, endpoint detection and email filtering are all built to sit between a malicious file, link or login attempt and your systems. None of them sit between a human being and a phone call. A voice call that impersonates a colleague or an IT help desk does not touch any of that infrastructure at all - it goes straight to the one component no software update can patch, which is a person under mild pressure trying to be helpful.
This is also why the MFA code being stolen in real time mattered more than the password. A stolen password alone is often useless against a well-configured MFA setup. A password and a live MFA code relayed to the attacker within the same session defeats that setup completely, because from the system's point of view the login looks exactly like the genuine employee logging in with their own second factor, seconds apart.
The fix is a protocol, not a product
There is no product to buy that closes this gap, because the gap is not technical. Any organization where a small number of staff can approve large financial transactions - which describes most private equity, asset management and treasury functions, and plenty of ordinary mid-sized businesses too - should establish and actually drill an out-of-band verification protocol for any unexpected call from IT or a colleague that asks for a credential, an MFA code, or urgent action.
The protocol itself is simple: hang up, and call back on a known internal number you looked up yourself, not one given to you during the call. Never re-enter a password or MFA code into a link received during a call, however convincing the site looks. Treat urgency itself as the tell - genuine IT support rarely needs a credential read aloud over the phone in the next two minutes.
The lesson generalizes well past finance. Any EU or UK business with a small number of high-authority individuals - finance approvers, IT administrators, executives with wire authority - fits the same target profile the attackers were working from. In the UK, the National Cyber Security Centre publishes guidance on vishing and social engineering that is worth building this drill around; in the EU, firms already subject to DORA or the incident-reporting duties under NIS2 should treat a successful vishing compromise as exactly the kind of incident those frameworks expect them to detect and report.
Read next: No Human Chose the Exploit, CISA Sets 2 Days | Rotate Every CI Credential You Used on 4 August



