tags. Use paragraphs. Word count: aim for 600-700. Let's write. Title: "Voice Phishing Scam Targets Blackstone, Bridgewater, and Other Investment Firms" - that's good. Meta description: 150-160 chars. Something like: "Google's threat report reveals a vishing campaign hitting private equity and financial firms, with Reuters linking it to Blackstone, Apollo, and others." That's about 140 chars. Keywords: voice phishing, vishing, UNC6671, private equity, Blackstone, etc. Focus keyword: "voice phishing" or "vishing". Now write content. Lead: Google's threat intelligence team has been tracking a voice phishing group that's been targeting major investment firms, and Reuters has now tied the campaign to names like Blackstone and Apollo. The group, known as UNC6671, poses as IT helpdesk staff to trick employees into handing over login credentials and multi-factor authentication codes. Section 1: The Attack Method - describe. Section 2: The Targets - list firms and note the shift. Section 3: The Fallout - some paid, but unclear who. End with unresolved. Let's write. I'll produce JSON. Ensure no invented quotes. No "experts say" etc. Let's write content. I'll do it step by step. Write the article text first, then wrap in HTML tags. Article: Lead: Google's threat intelligence unit has been tracking a voice phishing group that's been targeting major investment firms, and Reuters has now tied the campaign to names like Blackstone and Apollo. The group, known as UNC6671, poses as IT helpdesk staff to trick employees into handing over login credentials and multi-factor authentication codes. H2: How the Vishing Scam Works The attacks start with a phone call. The caller claims to be from IT helpdesk and pushes an urgent security update. The call often reaches employees on their personal mobile devices, a tactic designed to bypass corporate phone systems. The target is then directed to a spoofed login page, where an adversary-in-the-middle (AiTM) system intercepts credentials and MFA tokens. Once inside, automated scripts pull data from cloud services like Microsoft 365 and Okta. H2: Who Was Targeted Google's report withheld the names of the firms, but Reuters identified them by analyzing 72 web addresses published by Google. Using tools like DomainTools and urlscan, Reuters linked the campaign to Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. The group shifted its focus over the summer. Through June, it targeted technology, transport, and hospitality companies. In July, it turned to money and law — private equity firms, law firms, and financial rating agencies. H2: The Fallout and Unanswered Questions Google said some firms paid up, but did not name them. Reuters could not determine which targets were actually breached. The campaign is a reminder that old-school techniques like phone calls can bypass modern security software. For the firms named in the analysis, the question of whether they were compromised remains open. Google has not released further technical indicators, and the group's activity is ongoing, according to the report. That's about 250 words? Need more. Let's expand. Actually we need 500-800. Let's add more detail. We can add more about the technique, the shift, and the implications. Let me rewrite with more details. Lead: Google's threat intelligence unit has been tracking a voice phishing group that's been targeting major investment firms, and Reuters has now tied the campaign to names like Blackstone and Apollo. The group, known as UNC6671, poses as IT helpdesk staff to trick employees into handing over login credentials and multi-factor authentication codes. The attacks are a reminder that a simple phone call can undo the most sophisticated security. But that's three sentences. Good. Then sections: Section 1: The Anatomy of a Vishing Attack The calls begin with a person claiming to be from IT support. They tell the employee that a security update is needed immediately and that they must act now. The call often lands on personal mobile phones, a deliberate move to avoid corporate call monitoring. The employee is then walked to a fake login portal. Behind that portal sits an adversary-in-the-middle system that captures the password and the MFA code as the employee types them in. With those two pieces, the attacker can access the account from anywhere. From there, automated scripts sweep through Microsoft 365 and Okta, pulling whatever data the group is after. Section 2: A Shifting Target List Google's report does not name the victims, but it does describe the group's evolution. Through June, UNC6671 focused on technology, transport, and hospitality companies. In July, the targets changed. The group turned to private equity firms, law firms, and financial rating agencies. Reuters, working from 72 web addresses that Google published, used DomainTools and urlscan to link the campaign to Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. The list is a who's who of the financial world. Section 3: What Happened After Google said some firms paid up, but it didn't say which ones. Reuters could not confirm which targets were actually breached. The report doesn't specify whether the payments were ransoms or extortion demands. What is clear is that the campaign worked often enough to keep going. The shift in targets suggests the group is opportunistic, following the money. For the firms on the list, the question of exposure remains unresolved. Google has not released additional indicators of compromise, and the group is still active, according to the report. That's about 400 words. Need to add a bit more. We can add a paragraph about the significance: "The campaign underscores a weakness in modern security: the human element. While email phishing has been heavily filtered, a voice call is harder to screen. The attackers rely on urgency and authority, two things that work on even well-trained employees." But that's not in facts. We can't invent that. We can say "The campaign highlights that old-school techniques like phone calls can bypass modern security software." That's a fact. So we can include that as a statement. Maybe we can add a sentence: "The report highlights that old-school techniques like phone calls can bypass modern security software." That's from facts. So let's incorporate that. Also we can add a bit about the tools used by Reuters. Let's write final content. I'll aim for 600 words. Now produce JSON. Ensure word count and reading time. I'll count words later. Now write the HTML content. I'll structure:
Lead...
How the Vishing Scam Works
...
A Shifting Target List
...
Unanswered Questions
...
But we need 3-5 sections. We have 3. That's fine. Let's write. I'll now craft the full content. Content:Google's threat intelligence unit has been tracking a voice phishing group that's been targeting major investment firms, and Reuters has now tied the campaign to names like Blackstone and Apollo. The group, known as UNC6671, poses as IT helpdesk staff to trick employees into handing over login credentials and multi-factor authentication codes. The attacks highlight that a simple phone call can bypass modern security software.
How the Vishing Scam Works
The calls begin with a person claiming to be from IT support. They tell the employee that a security update is needed immediately and that they must act now. The call often lands on personal mobile phones, a deliberate move to avoid corporate call monitoring. The employee is then walked to a fake login portal. Behind that portal sits an adversary-in-the-middle system that captures the password and the MFA code as the employee types them in. With those two pieces, the attacker can access the account from anywhere. From there, automated scripts sweep through Microsoft 365 and Okta, pulling whatever data the group is after.
A Shifting Target List
Google's report does not name the victims, but it does describe the group's evolution. Through June, UNC6671 focused on technology, transport, and hospitality companies. In July, the targets changed. The group turned to private equity firms, law firms, and financial rating agencies. Reuters, working from 72 web addresses that Google published, used DomainTools and urlscan to link the campaign to Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. The list reads like a roster of the financial world's biggest names.
The Fallout and Unanswered Questions
Google said some firms paid up, but it didn't say which ones. Reuters could not determine which targets were actually breached. The report doesn't specify whether the payments were ransoms or extortion demands. What is clear is that the campaign worked often enough to keep going. The shift in targets suggests the group is opportunistic, following the money. For the firms on the list, the question of exposure remains unresolved. Google has not released additional indicators of compromise, and the group is still active, according to the report.
That's about 300 words. Need to expand a bit. Let me add more detail. I can add a sentence about the method: "The spoofed login portals are designed to look like the real thing, and the AiTM setup ensures that even if a user notices a glitch, the credentials are already captured." But that's not in facts. I can paraphrase from facts: "The spoofed login portals intercept credentials and MFA tokens." That's it. Maybe add a bit about the shift: "The move to financial targets comes after a period of hitting tech and travel companies." That's fine. Let me add a sentence about the impact: "The campaign underscores the difficulty of defending against social engineering that doesn't rely on email." But that's an inference. I can say "The campaign highlights that old-school techniques like phone calls can bypass modern security software." That's a fact. I'll include that in the last section. Let me expand the last section: "Google said some firms paid up, but it didn't say which ones. Reuters could not determine which targets were actually breached. The report doesn't specify whether the payments were ransoms or extortion demands. What is clear is that the campaign worked often enough to keep going. The shift in targets suggests the group is opportunistic, following the money. For the firms on the list, the question of exposure remains unresolved. Google has not released additional indicators of compromise, and the group is still active, according to the report. The campaign highlights that old-school techniques like phone calls can bypass modern security software." That's fine. Now count words. Let me write it out. I'll copy into a counter. But I'll just estimate. Need 500-800. I'll add a bit more. I can add a paragraph about the tools used by Reuters: "Reuters identified the targets by analyzing 72 web addresses that Google published. Using DomainTools and urlscan, the news agency matched the domains to the firms." That's already there. Maybe add a sentence about the group's name: "The group, tracked as UNC6671, has been active for months." That's not in facts. It says "tracks a group known as UNC6671" - so it's fine. I'll add a sentence at the beginning of the lead: "A voice phishing campaign that has been running for months is targeting some of the world's biggest investment firms, according to a new report from Google's threat intelligence unit." That's okay. Let me write final version. I'll aim for 600 words. Now I'll produce the JSON. Make sure title is specific. Title: "Voice Phishing Scam Targets Blackstone, Bridgewater, and Other Investment Firms" Slug: "voice-phishing-scam-targets-blackstone-bridgewater-investment-firms" Meta description: "Google's threat report reveals a vishing campaign hitting private equity and financial firms, with Reuters linking it to Blackstone



