{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:38:21.436Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks","date":"2026-08-06","date_precision":"day","victim_org":"Point72, Millennium Management, Two Sigma, Citadel and private-equity firms","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.","outcomes":["Attempt Blocked","Extortion","Credential Theft"],"loss_usd":10600000,"loss_note":"Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.","records_affected":null,"threat_actor":"UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon","summary":"BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.","how_it_worked":"Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.","lessons":"Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.","confidence":"Confirmed","sources":[{"title":"Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group","url":"https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at","year":2026,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"}]}