Hackers use old-school phone scams to breach financial firms

Hackers use old-school phone scams to breach financial firms

The attackers reportedly impersonated company help desks, convincing employees to reset passkeys or multifactor authentication through fraudulent websites.

Hackers have launched a wave of phone-based phishing attacks against prominent US financial firms, relying on social engineering rather than technical exploits to breach corporate accounts.

Advertisement

Google said the attackers, tracked under aliases including Redact, Pink, Falcon, and Helix, targeted private equity firms, financial services companies, law firms, and ratings agencies by posing as internal IT support staff. Employees were directed to fake passkey or multifactor authentication portals designed to capture login credentials and authentication codes during live phone calls.

According to Reuters, dozens of malicious domains were linked to organizations including Blackstone, Apollo, Bain Capital, KKR, TPG, CME Group, Bridgewater Associates, and Moody’s.

Google said the campaign appeared financially motivated, with attackers seeking access to sensitive corporate data that could be used to demand ransom payments.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Hackers use old-school phone scams to breach financial firms

Hackers use old-school phone scams to breach financial firms

The attackers reportedly impersonated company help desks, convincing employees to reset passkeys or multifactor authentication through fraudulent websites.

Share

Add us on Google

Hackers have launched a wave of phone-based phishing attacks against prominent US financial firms, relying on social engineering rather than technical exploits to breach corporate accounts.

Advertisement

Google said the attackers, tracked under aliases including Redact, Pink, Falcon, and Helix, targeted private equity firms, financial services companies, law firms, and ratings agencies by posing as internal IT support staff. Employees were directed to fake passkey or multifactor authentication portals designed to capture login credentials and authentication codes during live phone calls.

According to Reuters, dozens of malicious domains were linked to organizations including Blackstone, Apollo, Bain Capital, KKR, TPG, CME Group, Bridgewater Associates, and Moody’s.

Google said the campaign appeared financially motivated, with attackers seeking access to sensitive corporate data that could be used to demand ransom payments.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.