Hackers use old-school phone scams to breach financial firms
The attackers reportedly impersonated company help desks, convincing employees to reset passkeys or multifactor authentication through fraudulent websites.
Hackers have launched a wave of phone-based phishing attacks against prominent US financial firms, relying on social engineering rather than technical exploits to breach corporate accounts.
Google said the attackers, tracked under aliases including Redact, Pink, Falcon, and Helix, targeted private equity firms, financial services companies, law firms, and ratings agencies by posing as internal IT support staff. Employees were directed to fake passkey or multifactor authentication portals designed to capture login credentials and authentication codes during live phone calls.
According to Reuters, dozens of malicious domains were linked to organizations including Blackstone, Apollo, Bain Capital, KKR, TPG, CME Group, Bridgewater Associates, and Moody’s.
Google said the campaign appeared financially motivated, with attackers seeking access to sensitive corporate data that could be used to demand ransom payments.