A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.

The attribution comes after Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in recent attacks that relied on voice phishing (vishing) to trick employees into granting the attackers access to corporate systems.

Point72 reportedly told investors that it had been attacked but had not found evidence that client data was stolen, while Two Sigma said it had blocked an attempted intrusion and found no indication that its systems or data were affected.

Millennium declined to comment in response to questions from BleepingComputer. Citadel also declined to comment and referred BleepingComputer to Bloomberg’s reporting. Point72 and Two Sigma did not respond to requests for comment.

In response to questions from BleepingComputer, Austin Larsen, a principal threat analyst at Google’s Threat Intelligence Group (GTIG), said the company tracks the vishing activity as UNC6671.