Major US Hedge Funds Targeted in Vishing and Extortion Campaign
A sophisticated cyberattack campaign has targeted prominent US financial and legal institutions, including Blackstone, KKR, and CME Group. According to Google's Threat Intelligence team, the threat group known as BlackFile, or Redact, uses phone-based social engineering to impersonate IT staff, steal authentication credentials, and exfiltrate enterprise data for extortion. Investigators tracked $10.7 million in cryptocurrency tied to the operation.
Key points
- Google's Threat Intelligence team linked the cybercrime group BlackFile, also known as Redact, to an ongoing extortion campaign targeting major US hedge funds and law firms.
- Prominent victims targeted by the threat actors include major financial and corporate entities such as Blackstone, KKR, Apollo, CME Group, and the law firm Paul Hastings.
- The attackers execute voice phishing by impersonating internal IT personnel over the phone to trick employees into surrendering SaaS login credentials and authentication tokens.
- Investigators tracked $10.7 million flowing into 18 distinct cryptocurrency wallets between January and May 2026 as part of the criminal enterprise.
- After breaching enterprise systems like Microsoft 365 and Okta, the perpetrators exfiltrate sensitive data and threaten public leaks on the dark web unless ransoms are paid.
A sophisticated cyberattack campaign has targeted several prominent United States financial institutions and law firms, utilizing voice phishing and extortion tactics to compromise enterprise networks. According to reports from Google's Threat Intelligence team, the threat actor previously identified as BlackFile—and currently operating under the moniker Redact—has been executing coordinated intrusions against major market players.
The modus operandi involves social engineering via telephone communications. The perpetrators routinely impersonate corporate IT support personnel to deceive employees into visiting spoofed, lookalike login portals. These fraudulent sites are engineered to harvest valid credentials and authentication tokens for enterprise software-as-a-service platforms, including Microsoft 365 and Okta. Once inside, the actors leverage automated tools to siphon sensitive corporate data before issuing extortion demands threatening public leaks on the dark web.
High-profile targets identified in the campaign include major investment firms and financial exchanges such as Blackstone, KKR, Apollo, and CME Group, alongside legal institutions like Paul Hastings. Financial tracking by security researchers revealed that approximately $10.7 million flowed into 18 specific cryptocurrency wallets linked to the campaign between January and May 2026. The incidents highlight ongoing vulnerabilities in human-element security across the financial sector.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.