The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 12:43 pm AEST · 7 August 2026

Hedge funds targeted by UNC6671 extortion group using voice phishing – reports

Hedge funds targeted by UNC6671 extortion group using voice phishing – reports
Photograph: BleepingComputer

Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel and several private-equity firms have been targeted in a recent wave of cyberattacks by UNC6671, an extortion group linked to the BlackFile campaign, Reuters and Bloomberg reported. The attacks used voice phishing to trick employees into granting access to corporate systems; Point72 said it found no evidence client data was stolen, while Two Sigma said it blocked an attempted intrusion.

Google's Threat Intelligence Group tracks the activity as UNC6671, which previously operated under the "BlackFile" brand and has since diversified across multiple extortion brands including Redact, Pink, Helix and Falcon, according to threat analyst Austin Larsen. The group initially targeted retail and hospitality organisations before shifting in July 2026 toward private-equity firms, hedge funds, law firms and financial-rating agencies.

Attackers contact employees on personal phones while impersonating corporate help desks, directing them to phishing websites that steal credentials and session cookies, Lawrence Abrams reports for BleepingComputer.

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. bleepingcomputer.com
cybersecurityfraud-scamsextortionfinancephishing

Follow the live coverage →

Hedge funds targeted by UNC6671 extortion group using voice phishing – reports | The Financial Register Inward Money