What happened
BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.
How the deception worked
Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.
AI involvement · Unknown
Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.
The control that would have caught it· our reading, not a claim from the sources
Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.