AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion Group — Threadlinqs Intelligence
As of 2026-08-09, AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion Group is a high-severity phishing threat attributed to UNC6671 (multi-brand extortion cluster: BlackFile, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1963 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: UNC6671 (multi-brand extortion cluster: BlackFile · FINANCIAL
On August 5, 2026, a coordinated wave of AI voice-cloning vishing attacks targeted Point72 Asset Management, Citadel, Two Sigma Investments, and Millennium Management, with attackers impersonating IT
Beginning August 5, 2026, four of Wall Street's largest hedge funds — Point72 Asset Management, Citadel, Two Sigma Investments, and Millennium Management — along with several unnamed private-equity firms were targeted in a coordinated voice-phishing (vishing) campaign that used AI voice-cloning to impersonate trusted IT support staff and colleagues. Attackers called employees and IT help-desk agents directly (in some cases dialing personal mobile numbers rather than office lines to bypass corporate call-monitoring controls), used a cloned voice replicating a trusted colleague's or IT technician's tone and phrasing, and pressured the target into an urgent 'security migration' or 'passkey enrollment' pretext — asking the help-desk agent to reset MFA/credentials or enroll a new authentication device in real time.
Point72 notified investors it had been hit and that its initial review found no client data had been stolen, though the investigation was continuing; the firm declined further public comment. Two Sigma stated it successfully blocked the attempt with no impact to data or systems. Citadel and Millennium Management declined to comment on whether their defenses were breached. FINRA confirmed its Financial Intelligence Fusion Center (FIFC) — a near-real-time threat-intelligence-sharing portal for member firms launched March 31, 2026 — was activated and in contact with affected firms, marking the FIFC's first live operational test since launch.
While the source reporting on Point72 specifically noted 'Scattered Spider' only as a group known for similar social-engineering tactics historically (against targets such as Erie Insurance and Aflac) without confirming direct attribution, subsequent technical reporting (BleepingComputer, Google Threat Intelligence Group/Mandiant, The Hacker News) ties the TTPs and timing of this campaign to UNC6671 — a financially motivated data-theft extortion cluster that has operated under the brand names BlackFile (emerged February 2025, retired/disputed-shutdown May 11, 2026), Redact (rebrand announced June 27, 2026), and the concurrently active Pink, Helix, and Falcon brands. GTIG assesses a single core intrusion group likely drives the helpdesk-vishing and cloud-data-theft activity behind these brands, based on shared phishing-panel infrastructure, code/template reuse, and continued Bitcoin cashouts through the disputed 'shutdown' period. UNC6671's targeting shifted from manufacturing/healthcare/real-estate/technology/transportation/hospitality sectors toward private equity, hedge funds, major law firms, and financial-rating agencies starting July 2026 — directly preceding the August 5 hedge-fund wave.
UNC6671's documented kill chain: vishing calls to personal mobile devices posing as corporate IT help desk mandating urgent FIDO2 passkey enrollment or MFA changes; victims/agents directed to adversary-in-the-middle (AiTM) phishing portals on lookalike 'passkey'/'sso' domains that harvest credentials and session/MFA tokens in real time; attacker-controlled MFA devices registered on the compromised account while legitimate MFA and password-reset notification emails are deleted to evade detection; the compromised Okta/Microsoft Entra ID SSO account is then used as a single point of entry into connected SaaS platforms (Microsoft 365, Google Workspace, Salesforce and its OAuth-connected ecosystem); automated, script-driven bulk data exfiltration follows (identifiable by non-human user-agent strings hitting cloud APIs), after which the group extorts victims via brand-specific data-leak sites, with initial demands of $1-3M USD typically settling around $750K (a 50-75% reduction) in the majority of tracked cases. Between January 7 and May 12, 2026 alone, GTIG tracked ~141.65 BTC (~$10.6-10.7M USD) in ransom payments across 18 wallets tied to the BlackFile era of the operation.
Target sectors: financial services, hedge funds, asset management, private equity, legal services, financial rating agencies
Target regions: North America, united states of america
Timeline
- BlackFile extortion brand first emerges, initially targeting retail and hospitality sectors
- GTIG begins tracking BlackFile-era Bitcoin ransom payment window (through May 12, 2026), ultimately totaling ~141.65 BTC (~$10.6-10.7M USD) across 18 wallets
- AiTM phishing domains activatepasskey[.]com and enrollpasskey[.]com registered via TUCOWS, fronted by Cloudflare, targeting financial services/hospitality/energy
- Bridge domain passkeydeploy[.]com registered, later observed linking BlackFile-branded to Pink-branded victim campaigns
- BlackFile brand shutdown publicly announced; Bitcoin cashouts to BlackFile wallets continue afterward, contradicting the announced shutdown
- AiTM domains oskeysync[.]com and keysyncos[.]com registered (NICENIC/EZYDOMAIN) for Helix-branded targeting of financial services and legal sector victims
- Redact extortion brand publicly launches, describing itself as a rebrand necessitated by a compromised/rogue BlackFile affiliate
- UNC6671 targeting pivots from manufacturing/healthcare/real-estate/technology/transportation/hospitality toward private equity, hedge funds, major law firms, and financial-rating agencies
- passkeyhelpdesk[.]com registered (NICENIC, Cloudflare/Private Layer), later observed serving both Falcon- and Helix-branded victim campaigns simultaneously — evidence of shared operator infrastructure
- Coordinated AI voice-cloning vishing attacks strike Point72, Citadel, Two Sigma, and Millennium Management; Two Sigma blocks the attempt outright; FINRA's Financial Intelligence Fusion Center is activated for affected member firms in its first live operational test
- Fortune, TechTimes, InvestmentNews, TechNadu, and Benzinga report on the coordinated hedge-fund vishing wave and FINRA FIFC activation
- Point72 formally notifies investors of the incident, stating its initial review found no client information had been stolen, and declines further public comment; The Cyber Express publishes coverage citing possible Scattered Spider TTP overlap without confirming attribution
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
14 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1598, T1566, T1557, T1110, T1098, T1556, T1550, T1087, T1526