A cybercrime group called BlackFile is actively targeting major financial firms, law firms, and rating agencies — and it's not slowing down. Researchers at Google Threat Intelligence Group say the group hits an average of 1.5 new victims daily, with malicious infrastructure spotted targeting Blackstone, Bain Capital, Moody's, CME, and Apollo.
BlackFile runs four extortion brands — Redact, Pink, Helix, and Falcon — using voice-phishing and IT impersonation to gain access. Demands typically start around $3 million but get negotiated below $1 million. Some recent victims have received threatening messages and have even been swatted (a tactic where false emergency calls are used). Mandiant has responded to over two dozen confirmed breaches since January.
Source: CyberScoop