Cyber Threat Actor: Falcon
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
1 incident |
|---|
Characteristics
Profile
The threat actor is known publicly by the alias Falcon, and has also been observed using the names Helix, Pink, and Redact in related intrusions. These aliases appear in reports that link the group to a series of attacks on financial institutions. The actor’s activity has been linked to data theft and ransom extortion. No public attribution to a state sponsor or criminal alliance has been made.
Targeting is concentrated on financial and private equity firms, as demonstrated by the breach of Apollo disclosed in mid‑2026. Reporting indicates that ransom demands associated with these intrusions have reached up to seven hundred fifty thousand dollars. No specific geographic region is mentioned in the available reporting. The actor’s activity is described as financially motivated.
Initial access is achieved through social engineering, specifically spoofed helpdesk calls that persuade employees to reveal their credentials. Once inside the victim’s cloud environment, the actor exfiltrates personal information such as names, birth dates, addresses, and Social Security numbers. The source material does not reference any particular malware families, custom tools, or post‑exploitation frameworks. The described TTPs rely primarily on deception and legitimate account usage.
A representative example of the actor’s activity is the July 1, 2026 intrusion into Apollo’s cloud systems, which was disclosed in a filing with California’s attorney general. This incident is presented as part of a broader campaign in which the aliases Falcon, Helix, Pink, and Redact target similar firms with the same social engineering technique. The Apollo breach resulted in the exposure of employee and possibly affiliate data, though the exact scope was not detailed in the public notice. No further publicly reported operations have been attributed to the group beyond this example.