Key facts
- Hackers targeted dozens of U.S. financial institutions and other businesses using phone calls to compromise victims.
- Websites were created to steal employee passwords and multi-factor authentication codes.
- Prominent firms targeted include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, and Moody's.
- Google identified the hacking groups as operating under names such as Redact, Pink, Falcon, and Helix.
- Experts note the continued effectiveness of low-tech social engineering tactics against sophisticated security measures.
Ransom-seeking hackers have targeted numerous prominent U.S. financial institutions and other businesses over the past month using sophisticated phone-based social engineering tactics, according to data reviewed by Reuters and a blog post by Google.
The hackers devised websites specifically designed to steal passwords and multi-factor authentication codes from employees of targeted firms. Among the companies identified as targets were major private equity firms such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, and TPG, as well as CME Group and Moody's.
Google stated that the hacking groups operate under various names, including Redact, Pink, Falcon, and Helix, and that they often target industries based on financial calculations, believing these organizations possess sensitive data worth paying a ransom for. Google indicated that some companies paid ransoms, though it did not name them or specify which intrusions were successful.
Experts highlight that despite advanced security measures and AI-driven threats, traditional low-tech tactics like phone calls remain highly effective. Lee Clark, a cyberthreat intelligence manager, noted that the human element is consistently exploited. Austin Larsen, a threat analyst at Google, described the tactic as "really effective" rather than "sophisticated."
Google identified 72 malicious websites used in these attempted intrusions, though not all attempts were successful. The hackers would impersonate company help desks, directing employees to fake websites to harvest credentials and account access live over the phone.
