🔒Google Warns of UNC6671 Hacking Groups Targeting Finance
Hackers Using Vishing to Steal Data from Big Banks
TL;DR
Google's security team identified a hacking collective, UNC6671, targeting financial firms with vishing attacks. These groups steal sensitive data and threaten to publish it unless ransoms are paid, often demanding millions.
Google's security researchers have uncovered an extensive hacking operation dubbed UNC6671 that targets large financial institutions through sophisticated voice phishing (vishing) attacks. The hackers use social engineering tactics like impersonating IT staff or colleagues over the phone to trick employees into revealing their credentials and MFA codes on fake websites. This data is then used for extortion, with threats of public disclosure unless hefty ransoms are paid. One cryptocurrency wallet linked to these groups has received around $10 million in Bitcoin this year alone. The hackers typically demand between $750,000 and $3 million from their victims.

Key Points
UNC6671 targets large financial institutions in the US using voice phishing techniques to gain access to sensitive information.
Hackers use social engineering tactics like impersonating IT staff or colleagues over the phone to trick employees into revealing their credentials and MFA codes on fake websites.
One cryptocurrency wallet associated with UNC6671 has received around $10 million in Bitcoin this year, indicating significant success in their operations.
The hackers typically demand ransoms ranging from $750,000 to $3 million from victims threatened with data leaks if payments are not made.
Google's researchers believe these hacking groups may be a coordinated entity operating multiple public extortion brands to compartmentalize operations.
Why It Matters
If you're in finance or work for any company handling sensitive financial data, this is critical. UNC6671 uses vishing attacks to steal credentials and extort millions from victims. For example, a legal firm might face threats of data leaks unless they pay up to $3 million in ransom. This highlights the need for robust social engineering training and multi-layered security measures.
Frequently Asked Questions
Why does this matter?
If you're in finance or work for any company handling sensitive financial data, this is critical. UNC6671 uses vishing attacks to steal credentials and extort millions from victims. For example, a legal firm might face threats of data leaks unless they pay up to $3 million in ransom. This highlights the need for robust social engineering training and multi-layered security measures.
What happened?
Google's security team identified a hacking collective, UNC6671, targeting financial firms with vishing attacks. These groups steal sensitive data and threaten to publish it unless ransoms are paid, often demanding millions.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.