Blackstone, KKR and CME named in vishing infrastructure, not confirmed breaches
Reuters identified Blackstone, KKR and CME in company-specific phishing domains tied to a vishing campaign, but no breach was confirmed.
By Wei-Lin Zhao · AI Correspondent
· 3 min read
Blackstone, KKR and CME Group appeared in company-specific phishing infrastructure linked to a vishing and extortion campaign, but available reporting does not establish that any of the three suffered a breach. In the Blackstone KKR CME vishing campaign, Reuters identified malicious subdomains tailored to the firms after examining 72 sites listed in Google threat research.
Google did not publicly name the targets in its research. Reuters said its review of the domains and web-intelligence data also identified apparent targeting of Apollo Global Management, Bain Capital, Bridgewater Associates, TPG and Moody's. A Google threat analyst told Reuters the subdomains were likely used in attempted intrusions, while cautioning that the attempts were not all successful.
Reuters could not determine which organizations, if any, were compromised. KKR and CME declined to comment, while Blackstone did not immediately respond, according to the report. That distinction matters: a phishing domain carrying a company name is evidence of intended targeting, not proof that an employee gave up access or that data was taken.
Were Blackstone, KKR and CME breached?
No confirmed breach at Blackstone, KKR or CME was reported in the material reviewed by Reuters. The campaign has been associated with the intrusion cluster Google tracks as UNC6671, which earlier operated under the BlackFile extortion brand. In later reporting, the activity involved extortion labels including Redact, Pink, Falcon and Helix. SiliconANGLE reported that the brands shared phishing infrastructure and, in some cases, phishing templates.
Google's Threat Intelligence Group said UNC6671 had targeted dozens of organizations in North America, Australia and the UK since emerging in early 2026. Its earlier activity included retail and hospitality companies, according to BleepingComputer. Google has described the campaign as social engineering rather than a vulnerability in a vendor product or corporate infrastructure.
How the vishing calls sought access
The method starts with a phone call, often to an employee's personal mobile number. Callers pose as internal IT or help-desk staff, sometimes using a spoofed number that appears to belong to the employer. They tell the employee that a passkey migration or multifactor-authentication update is required and steer them to an organization-branded lookalike login page.
Google reported that an adversary-in-the-middle proxy captured passwords and live session tokens, which could give attackers access beyond a password alone. The callers also sought MFA codes or approvals in real time. After access, Google said, the actors could register an attacker-controlled MFA device, then use single sign-on access to reach Microsoft 365, Okta, SharePoint, OneDrive, Salesforce, Zendesk and connected services.
Google's reporting gives security teams several concrete signals to investigate: unscheduled passkey-enrollment calls, new MFA-device registrations, and Microsoft 365 activity that claims to be Microsoft Office while using Python or PowerShell user agents. The group used automated methods, including Microsoft Graph and direct web requests, to retrieve files. Google warned that such activity may appear as FileAccessed rather than FileDownloaded in audit logs, reducing its visibility for teams that focus mainly on download events.
For financial firms, the attacker's apparent rationale was sensitive information that could create extortion leverage. A Google analyst told Reuters that the group selected sectors based on the value of the data it expected to find and the prospect that victims would pay to keep it private.
This story draws on original reporting from SiliconANGLE.