"This Is IT, We Need to Migrate Your Account": The Vishing Campaign Hitting Financial Firms
Dozens of US financial institutions, including private equity firms, hedge funds, asset managers and financial-data companies, have been targeted in a voice-phishing campaign. The call does the persuading, and a spoofed login portal captures everything.
Law firm Goodwin summarised the campaign on 4 September 2026. Google's Threat Intelligence Group tracks the actors as UNC6671 and links them to the Redact, Pink, Helix and Falcon extortion brands. Ransom demands reportedly range from $750,000 to $3 million per victim. At least one large asset manager has confirmed a breach that exposed names, dates of birth, contact details and Social Security numbers.
How the attack works
- The call: an employee gets a call on their personal mobile, outside the company's phone and email security.
- The pretext: the caller says they're from the IT helpdesk and that an urgent security migration needs the employee to sign in now.
- The portal: the employee is sent to a spoofed login page running adversary-in-the-middle (AiTM) infrastructure.
- The capture: the AiTM proxy passes the login through to the real service and records the password, the MFA code and the session as they go by.
AiTM is why "we have MFA" isn't enough. A code from an authenticator app, an SMS or a push approval can all be relayed in real time. The victim really does log in, and so does the attacker.
Your IT team doesn't need to call your personal phone and watch you sign in. If a call ends with "open this link and log in", hang up and call IT back on a number you already have.
The recommendations
- Train for the phone, not just email. Give people a clear way to escalate a suspicious call without worrying about looking rude.
- Make helpdesk identity checks as strict as a wire transfer. Both directions: IT verifying callers, and staff verifying "IT".
- Move to phishing-resistant MFA. Passkeys and FIDO2 security keys are tied to the real domain, so an AiTM proxy on a lookalike domain can't relay them.
- Rehearse the cloud-compromise scenario that starts with a phone call, including revoking sessions, not just resetting passwords.
What gives the portal away
An AiTM page shows the real service's content, so how it looks tells you nothing. The domain gives it away. It isn't your company's single sign-on domain, and it's often a newly registered hostname that mixes your company name with words like "secure", "migration" or "sso". Check the address bar before you type anything, especially when someone on the phone is rushing you.
What a browser can still catch
The call is out of reach of any browser tool, but the portal isn't. PhishClean flags lookalike and brand-embedding domains and login forms that post to unexpected places. It also warns on HTTPS downgrades and hidden iframes, which proxy kits sometimes use. It does this locally, while you're being rushed.
Sources
Don't let a phone call rush you onto a fake portal
PhishClean flags lookalike login domains and suspicious forms in the browser, so a link given to you on a call gets a second opinion.
Install PhishClean FreeLast updated: