Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmed

Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks

Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · Financial Services · United States · August 6, 2026

Criminal proceeds
$10,600,000
What the attackers earned. Not the same as what the victims lost, and often much smaller.
Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.

What happened

BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.

How the deception worked

Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.

AI involvement · Unknown

Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.

The control that would have caught it· our reading, not a claim from the sources

Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.

Sources (1)

  1. Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.