Key facts
- Unknown hacking groups are targeting major financial firms.
- Hackers use phone calls to trick employees into revealing credentials.
- The goal is to steal sensitive data for extortion.
- Some groups have extorted victims for millions in Bitcoin.
- The attackers may operate under a larger collective.
- This tactic bypasses traditional security measures.
Unknown hacking groups are employing a sophisticated social engineering tactic involving direct phone calls to employees of major financial firms, according to Google's security researchers. The attackers aim to trick employees into revealing their credentials, which are then used to steal sensitive data for extortion purposes. These groups, which may operate under a larger collective, have successfully extorted victims for millions of dollars in Bitcoin. This method bypasses many traditional security measures by directly targeting human vulnerabilities. The researchers did not specify the exact number of firms targeted or the timeframe of these attacks, but highlighted the significant financial gains achieved by the attackers. The tactic involves impersonating trusted entities or colleagues to gain the employee's confidence before requesting sensitive information. The stolen data is then leveraged for financial gain through cryptocurrency, specifically Bitcoin, which is favored for its relative anonymity.
