September 25, 2026 - 6 min read

By PhishClean Research Team

"This Is IT, We Need to Migrate Your Account": The Vishing Campaign Hitting Financial Firms

Dozens of US financial institutions, including private equity firms, hedge funds, asset managers and financial-data companies, have been targeted in a voice-phishing campaign. The call does the persuading, and a spoofed login portal captures everything.

Law firm Goodwin summarised the campaign on 4 September 2026. Google's Threat Intelligence Group tracks the actors as UNC6671 and links them to the Redact, Pink, Helix and Falcon extortion brands. Ransom demands reportedly range from $750,000 to $3 million per victim. At least one large asset manager has confirmed a breach that exposed names, dates of birth, contact details and Social Security numbers.

How the attack works

AiTM is why "we have MFA" isn't enough. A code from an authenticator app, an SMS or a push approval can all be relayed in real time. The victim really does log in, and so does the attacker.

Your IT team doesn't need to call your personal phone and watch you sign in. If a call ends with "open this link and log in", hang up and call IT back on a number you already have.

The recommendations

What gives the portal away

An AiTM page shows the real service's content, so how it looks tells you nothing. The domain gives it away. It isn't your company's single sign-on domain, and it's often a newly registered hostname that mixes your company name with words like "secure", "migration" or "sso". Check the address bar before you type anything, especially when someone on the phone is rushing you.

What a browser can still catch

The call is out of reach of any browser tool, but the portal isn't. PhishClean flags lookalike and brand-embedding domains and login forms that post to unexpected places. It also warns on HTTPS downgrades and hidden iframes, which proxy kits sometimes use. It does this locally, while you're being rushed.

Sources

Don't let a phone call rush you onto a fake portal

PhishClean flags lookalike login domains and suspicious forms in the browser, so a link given to you on a call gets a second opinion.

Install PhishClean Free

Last updated:

Share This Guide

If this helped, share it with someone who would benefit from it, or subscribe for new browser-security guides from PhishClean.