Cybersecurity group UNC6671 targeted at least eight major US financial institutions and private equity firms, including Blackstone and Apollo Global Management, using a voice phishing technique combining phone calls and fake websites. The attackers created 72 malicious websites designed to harvest employee credentials by impersonating IT support staff. Initial ransom demands ranged from $1 million to over $3 million, but negotiations brought payments down to approximately $750,000 on average, all paid in Bitcoin. The group’s activity intensified throughout July 2026, progressively refining their approach to focus on high-value financial data.
Source: Read the original article

