All field notes

Field note · Incident study

The Acquirer Is the Attack Surface

Over five weeks between early July and early August 2026, a coordinated crew that Google’s Threat Intelligence Group tracks as UNC6671 vished more than 200 enterprises. The list of named targets reads like a Wall Street directory: Blackstone, Apollo Global Management, KKR, Bain Capital, TPG, Clearlake Capital — every top private equity firm — plus Bridgewater Associates, Point72, Millennium, Two Sigma, and Citadel on the hedge fund side, plus CME Group and Moody’s. Same operator, previously ran as BlackFile, retired that brand in May, now operates as Falcon, Helix, Pink, and Redact.

The industry read is that financial firms are targets now. That’s true, and it’s not new. The durable read is that the targeting shift — toward firms involved in mergers, acquisitions, and capital deployment — is a piece of intelligence the M&A cyber diligence framework hasn’t caught up to. The threat actor mapped the deal surface before the deal team did.

200+Enterprises vished in the campaign
5Weeks, July–August 2026
72+Spoofed enterprise IT help desk sites
$10MBitcoin, one linked wallet, first months of 2026

The playbook

Four steps, in order. None of them require a novel exploit. All of them exploit assumptions the acquirer has already made about how work gets done, and every deal firm has made them.

01

Personal cellphone, not corporate line

The vishing calls hit employees’ personal cellphones, not the corporate desk line. This sidesteps the enterprise phone system’s spam filters and gives the caller a plausible pretext: this is an issue urgent enough not to route through IT tickets. Ground-truth of who works where at Blackstone or KKR is easy to buy. Ground-truth of an employee’s cell number is easy to correlate from data-broker leaks and past breaches.

Personal-device pretextOut-of-band channel
02

The pretext is an urgent security migration

The caller impersonates IT help desk or a coworker. The pretext is uniform across brands: an urgent security migration requires the employee to re-authenticate at a spoofed enterprise login page. It works because migrations are common, the caller sounds credentialed, and the target page is pixel-perfect. UNC6671 built 72+ phishing sites impersonating enterprise IT help desks to catch credentials and MFA codes at the moment of entry.

IT-help-desk impersonationMFA-code capturePixel-perfect spoofs
03

Credential is the entry point, not the payload

Post-compromise TTPs focus on data staging: identify what’s in the environment worth exfiltrating, package it, move it. The victim’s own tooling — file sync, cloud storage, dev environments, the CRM — often carries the payload out. Nothing here needs custom malware or a novel exploit chain. The valuable data at a PE or hedge fund isn’t just the target company’s books — it’s the diligence pack, the deal terms, the counterparty communications, the deal-team model output.

Living-off-the-landDiligence-pack exfiltrationDeal-team data
04

Branded extortion, businesslike posture

Ransom demands run $750K to $3M. One associated crypto wallet took in roughly $10M in Bitcoin in the first months of 2026 alone. The leak-site messaging is measured, not menacing: “Respond promptly and in good faith, and the matter is resolved without further incident.” Multiple extortion brands (Falcon, Helix, Pink, Redact) rotate to keep each brand’s reputation clean for the next round. Retire a brand when the pressure gets uncomfortable; stand up a new one; keep the crypto wallets.

Multi-brand extortion$750K–$3M demandsData-publication threat

The diligence gap

What the M&A cyber diligence framework currently asks, and what UNC6671’s targeting reveals about what it should ask.

What M&A cyber DD currently asksDirection: TARGET-INWARD
Is the target company secure?Control audits, SOC 2 status, prior-incident disclosure, patch cadence, EDR coverage.
What are the target’s material vendors?Third-party inventory, vendor risk matrix, subprocessor breach exposure.
What’s the target’s regulatory exposure?PCI, HIPAA, GDPR footprint. Fines waiting to happen.
What’s the target’s cyber insurance?Policy limits, exclusions, retro dates.
What UNC6671 already knows about the exposureDirection: ACQUIRER-OUTWARD
The acquirer is the custodian at close.If the acquirer’s own credential posture is weak, the acquired data is at risk from day one, regardless of what the target’s pre-close controls looked like.
Deal firms concentrate counterparty data.A firm doing 30 deals a year is holding 30 counterparties’ worth of PII, financials, and privileged communications. That concentration is targeting-attractive independent of any single deal.
Deal-team culture makes vishing look normal.Employees use personal devices for business, sit on multiple deal teams, and answer calls from unfamiliar numbers as a matter of course. Unusual is what everyone else’s culture looks like. This one was built to route calls fast and ask questions later.
The valuable data is the deal, not the target.The diligence pack, term sheet, counterparty communications, and deal-team model outputs are the exfil target. That data lives inside the acquirer, not the target.

The threat actor mapped the deal surface before the deal team did.

The bidirectional exposure problem — M&A cyber diligence is not just about what you’re buying, it’s about your own capacity to steward what you buy.

What Cyber Cost of Deal would and wouldn’t have changed

Cyber Cost of Deal (CCOD) is a pricing framework, delivered through Quantitative Cyber Diligence (QCD). It puts dollar values on the exposures inherent to a deal so the acquirer can decide whether to price them into the offer, negotiate them out of the terms, or walk away. It’s not an EDR, it’s not awareness training, it’s not a phishing-resistant-MFA rollout. The honest split matters.

×What it wouldn’t have fixed
The vishing calls themselves.

Preventing an analyst from being duped on a specific Tuesday is a phishing-resistant-MFA and call-verification-protocol job at the acquirer’s HR and IT layer. Not a diligence output.

UNC6671’s brand rotation.

Retiring BlackFile, standing up Falcon, Helix, Pink, Redact, and whatever comes next is an intelligence and law-enforcement problem. Pricing frameworks don’t interrupt threat-actor lifecycle management.

Point-in-time credential compromise.

No pricing framework stops the specific credential from walking out the door in the specific incident. What it does is make the expected cost of that class of incident legible enough to fund the controls that reduce it.

✓What it would have materially changed
Priced the acquirer’s posture, not just the target’s.

Cyber DD becomes bidirectional. The acquirer’s own credential-theft resilience, personal-device policy, and vishing-defense posture get a dollar line in the deal exposure. “If we close this deal at our current credential posture, expected annual loss during the integration window is $X, and we own it.”

Extended the exposure calculation to include stewardship capacity.

Given the target’s PII sensitivity and volume, and the acquirer’s demonstrated ability (or inability) to hold sensitive data safely, the priced expected loss for years 1–3 post-close is a defensible number. Not a heat map.

Turned “harden vishing defenses before close” into a math problem.

The most valuable output of QCD is a decision that used to live in the vibes column moving into the numbers column. “Deferring the phishing-resistant-MFA rollout to Q1 next year costs us $Y in expected loss across the deals we close this quarter” is the conversation an investment committee can actually have.

Our read

Three things we think this pattern makes true, in order of confidence.

One. UNC6671’s targeting shift is a preview, not a peak. Hitting firms that concentrate counterparty data is the beginning, not the ceiling. The next tier fits the same pattern with less mature credential defenses: law firms doing M&A work, valuation firms sitting on deal models, IB advisors holding the diligence packs, and mid-market portfolio companies at the point of investment. If you’re on the buy or sell side of a deal closing in the next six months, at least one of your advisors is on someone’s list.

Two. The “financial firms are targets” framing is going to age poorly. Firms will invest in vishing defenses, tighten personal-device policy, and roll out phishing-resistant MFA at the analyst tier. By mid-2027 the direct-vishing attack surface at Blackstone, KKR, and Apollo will be materially harder. The pressure will move. To the advisors. To portfolio companies at the point of investment. To the integration window post-close. The exposure isn’t going away. It’s migrating.

Three. The diligence framework has to catch up to where the exposure actually lives. Traditional M&A cyber DD scoped the transaction as a security question. The pattern makes it plain: it’s also a stewardship question and a pricing question. That’s what the PE cyber DD workflow becomes over the next 18 months: bidirectional pricing that captures the acquirer’s posture alongside the target’s, and the integration window alongside the deal. Not because we invented it. Because the threat actors are pricing it in already, and the market moves toward what attackers already price.

If you’re doing M&A cyber diligence today and want to see what bidirectional pricing looks like as a delivered artifact, that conversation starts on the vCISO Lite Cyber Cost of Deal page.

Primary sources