TLDRs:
- Google says voice-phishing calls are enabling breaches at major U.S. financial firms.
- Hackers impersonate IT staff to steal credentials and bypass multi-factor authentication.
- Ransom demands reportedly range from $750,000 to $3 million per victim.
- Investigators suspect several extortion brands may belong to a coordinated cybercrime network.
Google is warning that a wave of phone-based cyberattacks is helping hackers penetrate major financial institutions and demand millions of dollars in ransom, highlighting how traditional social-engineering tactics remain highly effective despite the rapid rise of AI-powered cyber threats.
The Alphabet-owned company’s security researchers said they have identified several hacking groups that are targeting large financial and investment firms across the United States. The attackers are not relying on sophisticated malware alone. Instead, they are calling employees directly, pretending to be internal IT staff or coworkers, and persuading victims to hand over login credentials and multi-factor authentication codes through fake websites.
The technique, known as voice phishing or vishing, has become a central component of the campaign, according to Google’s threat-intelligence team.
Phone Calls Trigger Breaches
The warning arrives as cybersecurity professionals increasingly focus on human-targeted attacks rather than purely technical exploits. Google said the attackers contact employees on their personal mobile phones, creating a sense of urgency and legitimacy that can make even well-trained staff vulnerable.
Researchers identified multiple groups involved in the activity, which they labeled Falcon, Helix, Pink, and Redact. The company believes these operations may be connected to a broader threat cluster it tracks under the name UNC6671, although it has not yet determined whether the groups are affiliates, splinter operations, or separate actors using the same phishing infrastructure.
The attackers reportedly use spoofed websites designed to resemble corporate login portals. Once employees enter their credentials and authentication codes, the hackers can gain access to internal systems, sensitive documents, and cloud environments.
Wall Street Firms Reportedly Targeted
Google did not publicly identify the affected organizations. However, reports citing people familiar with the matter said that several prominent private-equity, financial, and market-infrastructure firms were among the targets, including major investment managers and exchange operators.
The focus on organizations involved in mergers, acquisitions, capital deployment, and litigation suggests the attackers are seeking information with exceptionally high blackmail value. Confidential deal documents, investor data, legal records, and strategic communications can provide significant leverage during extortion negotiations.
Cybersecurity analysts say this represents a shift from indiscriminate ransomware attacks toward more selective campaigns aimed at companies where stolen data may be worth more than encrypted systems.
Extortion Websites Raise Pressure
Google said some of the groups operate dedicated leak sites where they publish claims about their intrusions and threaten to release stolen data if victims refuse to negotiate. This mirrors the increasingly common double-extortion model, in which criminals both steal and potentially publish information.
One of the sites reviewed by researchers presented the negotiations as a business transaction, warning that delays or refusal to engage could lead to public disclosure of the data. Such messaging is designed to increase pressure on corporate executives and legal teams.
The financial scale of the campaign appears significant. Google said a cryptocurrency wallet linked to one of the groups received roughly $10 million in Bitcoin during the first months of 2026. Individual ransom demands have reportedly ranged from $750,000 to $3 million.
Old Tactics Still Work
The report is notable because it underscores that relatively simple deception techniques can outperform more advanced attack methods. While AI tools are increasingly used for reconnaissance, phishing, and malware development, the initial compromise in these incidents often depended on convincing a person to take an action they should not take.
Security experts say organizations cannot rely solely on technical defenses. Employee verification procedures, call-back policies for IT requests, hardware security keys, and stronger authentication controls remain essential safeguards against vishing attacks.
Google also noted that similar actors have previously targeted companies in manufacturing, healthcare, insurance, transportation, hospitality, real estate, and technology sectors, seeking intellectual property, source code, and sensitive client information.
For investors, the report is less about an immediate financial impact on Alphabet and more about the growing importance of cybersecurity within cloud and enterprise businesses. As cybercriminals continue to combine psychological manipulation with targeted data theft, the latest warning suggests that the weakest point in many organizations may still be the human layer rather than the software stack itself.


