hackers target wall
| |

Hackers target Wall Street firms in phone-based cy…

NEW YORK: Hackers seeking ransom have targeted dozens of major US financial institutions and businesses using a surprisingly simple tactic — posing as IT help desk employees and tricking staff into handing over passwords and authentication codes.

According to Google and internet intelligence data reviewed by Reuters, the campaign targeted prominent private equity and financial firms, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.

Google said the cybercriminals operate under several names, including Redact, Pink, Falcon and Helix. The technology giant said some companies targeted during the campaign had paid ransoms, although it did not identify those businesses. Reuters was also unable to determine which companies were successfully compromised.

The hackers reportedly created websites designed specifically for individual companies. Employees were then contacted by phone, sometimes through calls that appeared to originate from their organisation’s legitimate IT help desk.

The attackers allegedly told employees that they needed to urgently update their passkeys or multifactor authentication credentials. Victims were then directed to malicious websites using names designed to look legitimate, such as those containing phrases like “passkey helpdesk” or “secure passkey”.

Once an employee entered their credentials, the hackers could obtain an authentication code in real time, allowing them to take control of the account while remaining on the phone with the victim.

Austin Larsen, a principal threat analyst with Google’s Threat Intelligence Group, said the technique was not especially sophisticated but remained highly effective.

Cybersecurity experts said the campaign demonstrates that human behaviour remains one of the biggest vulnerabilities for even heavily protected organisations. Lee Clark of the Retail and Hospitality ISAC compared the tactic to persuading a security guard to open a heavily protected gate.

Google said the attackers had increasingly focused on private equity firms, law firms and financial ratings agencies because they may hold sensitive information that companies would be willing to protect through ransom payments.

Reuters identified 72 malicious websites listed in Google’s report and linked several of them to specific companies using internet intelligence platforms. Google cautioned that while the infrastructure indicated attempted intrusions, not every attack was necessarily successful.

The campaign appears to have affected a broader range of industries. Data reviewed by Reuters showed that hackers created digital traps targeting more than 200 companies during a five-week period, including Uber, Zillow and Levi Strauss, along with law firms such as Paul Hastings and Greenberg Traurig.

The hacking group’s shifting aliases have also complicated efforts to identify those behind the attacks. Google said the various names appeared connected through shared infrastructure, but acknowledged that important questions about the hackers’ identities and relationships remain unanswered.

The latest campaign has heightened concern across Wall Street, highlighting how convincing phone calls and basic social engineering can bypass sophisticated cybersecurity systems and expose highly valuable corporate accounts.

Similar Posts

  • Southern Thailand Flood Death Toll Soars to 145, Recovery Efforts Intensify

    BANGKOK – The death toll from the catastrophic flooding in Southern Thailand has risen sharply to 145, with the province of Songkhla suffering the heaviest loss at 110 lives, Government spokesman Siripong Angkasakulkiat announced today. The figures, based on a report from the Public Health Ministry, mark one of the largest casualties from a disaster […]

  • | |

    Woman accused in $32 Million COVID-19 relief fraud extradited from Jamaica to the United States

    A woman accused of participating in a multimillion-dollar COVID-19 relief fraud scheme has been extradited from Jamaica to the United States after authorities located and arrested her while she was allegedly living under a false identity. Federal officials announced that 41-year-old Elaine Angene Escoe has been returned to South Florida, where she will face charges related to the alleged theft of more than $32 million in pandemic relief funds. According to investigators, Escoe left the United States last year after failing to appear for a scheduled federal court hearing. Authorities say she fled the country in an attempt to avoid prosecution and remained outside the United States for several months before her whereabouts were discovered. Law enforcement officials reported that Escoe traveled to Jamaica following her disappearance. Investigators eventually located her after receiving information about her location. During the investigation, authorities alleged that she had been living under the assumed name “Harley Newman” in an effort to conceal her identity and avoid arrest. FBI Director Kash Patel confirmed that Escoe had been taken into custody in Jamaica and successfully returned to the United States. In a statement, he said that the suspect, who had been a fugitive since May 2025, was captured while allegedly using a false identity and has now been brought back to face legal proceedings. Federal prosecutors allege that Escoe was involved in a large-scale fraud operation alongside five other individuals. According to the indictment, the group submitted numerous fraudulent applications to obtain money from government programs created to support businesses experiencing financial hardship during the COVID-19 pandemic. Investigators claim the applications contained false information, including fabricated tax documents, altered financial records, and counterfeit bank statements. Prosecutors allege that these fraudulent documents were used to convince authorities that the applicants qualified for financial assistance under pandemic relief programs. Authorities further allege that the group received millions of dollars through these fraudulent claims and also accepted substantial kickbacks from third parties connected to the scheme. The funds were reportedly intended to help legitimate businesses survive the economic challenges caused by the pandemic but were instead diverted through fraudulent activities. According to federal officials, the other five individuals accused in the case have already been convicted or pleaded guilty. Their prison sentences reportedly range from 42 months to nearly 20 years, depending on their level of involvement and the charges they faced. Escoe now faces multiple federal charges in Florida, including wire fraud and money laundering. If convicted, she could face significant penalties under United States federal law. Acting Attorney General Todd Blanche emphasized the government’s commitment to prosecuting individuals accused of abusing taxpayer-funded assistance programs. He stated that the Department of Justice will continue pursuing those who allegedly exploited emergency relief initiatives, regardless of how long investigations take or where suspects attempt to hide. Federal officials say the case demonstrates the extensive efforts made by law enforcement agencies to identify and prosecute individuals accused of committing financial crimes involving public funds. Investigators continue to monitor pandemic-related fraud cases across the country, many of which involve allegations of false loan applications, forged financial documents, and misuse of government assistance programs. The extradition of Elaine Angene Escoe marks the latest development in one of the larger COVID-19 relief fraud investigations pursued by U.S. authorities. As legal proceedings move forward, prosecutors are expected to present evidence supporting the allegations, while Escoe will have the opportunity to respond to the charges in court. The outcome of the case will ultimately be determined through the judicial process.

  • | |

    Hangu operation kills terror attack mastermind

    Security forces have killed the alleged mastermind of the July 30 attack on the Khazina Banda police checkpost in Hangu, where nine police personnel lost their lives. A senior security official told  that the terrorist, identified as Amir Mauviya, was killed during an intelligence-based operation in Chapri Naryab, Hangu. According to security sources, Mauviya held a key position within Fitna-al-Khawarij in Kurram and faced charges in several other terrorism cases. Security forces have intensified operations against militants under Operation 11 Garaj. The July 30 attack on the Khazina Banda checkpost killed nine police officials, including a deputy superintendent of police, and injured 28 others. Police said terrorists attacked the post, triggering an exchange of fire in which 15 militants were killed. In a separate incident on Sunday, an improvised explosive device targeted a police van near Pir Zakorhi Bridge, close to the Peshawar-Islamabad motorway toll plaza. The blast caused minor injuries to two police personnel. Earlier, on July 29, a police officer lost his life and four terrorists were killed during an operation in Matta tehsil of Swat. The latest incidents come days after a deadly attack on a joint police checkpost in Tank district, where 15 people, including 14 security personnel and a government official, were martyred. According to the military’s media wing, security forces killed 12 attackers after thwarting their attempt to breach the checkpost. One terrorist vehicle packed with explosives also struck the perimeter wall, causing significant damage. Khyber Pakhtunkhwa continues to face a growing threat from militant attacks. The Pakistan Institute for Conflict and Security Studies reported that security personnel deaths in terrorism-related incidents across KP, excluding the merged districts, rose from 12 in June to 38 in July. Terrorist deaths also increased from 37 to 108 during the same period, while civilian fatalities dropped from 26 to seven.

  • | |

    Pakistan, Spain discuss expanding trade, investmen…

    RAWALPINDI: Ambassador of Spain to Pakistan, H.E. Carlos Aragón Gil de la Serna, visited the Rawalpindi Chamber of Commerce & Industry (RCCI) and held a meeting with RCCI President Usman Shaukat to discuss ways to further strengthen bilateral economic, trade and cultural relations between Pakistan and Spain. Rana Mashhood Ahmad Khan, Coordinator to the Prime Minister’s Youth Programme, was also present as the chief guest on the occasion. Senior Vice President Khalid Farooq Qazi, Vice President Fahad Barlas, former presidents of RCCI, Executive Committee members and a large number of Chamber members also attended the meeting. Upon their arrival, the Spanish Ambassador and Rana Mashhood Ahmad Khan were warmly welcomed by RCCI President Usman Shaukat and members of the Chamber. RCCI President Usman Shaukat highlighted the significant potential for expanding Pakistan–Spain trade and called for stronger business-to-business linkages, improved market access, and enhanced cooperation in investment and technology. He said Spain offers important opportunities for Pakistani exporters, particularly in textiles and agro-based products, while Pakistan can benefit from Spanish expertise in modern agriculture, precision farming, irrigation, mechanization, greenhouse technology and water management. The discussion assumes added significance in light of recent Pakistan–Spain consultations regarding the establishment of a Joint Working Group on Agriculture. Pakistan has identified rice, ethanol, potatoes and maize as products with potential for increased exports to the Spanish market. Spain has also acknowledged Pakistan’s favourable trade balance, with textiles being among Pakistan’s major exports to Spain. On this occasion, Rana Mashhood Ahmad Khan highlighted RCCI’s important role in supporting the government on economic and budget-related matters and appreciated the Chamber’s contribution towards strengthening Pakistan’s economic foundations. He said Pakistan is moving forward across various sectors, particularly information technology, and stressed the need to further promote investment, innovation and entrepreneurship. Rana Mashhood said the Prime Minister’s Vision 2047 provides a roadmap for building a prosperous, self-reliant and globally competitive Pakistan. He emphasized that youth empowerment, employment generation, peace and economic stability are essential priorities for the country’s sustainable development. He added that Pakistan’s young population represents a major national asset and that greater opportunities for skills development, entrepreneurship and employment are needed to fully harness its potential. He also appreciated the growing economic and diplomatic engagement between Pakistan and Spain, saying stronger cooperation with European countries can create new opportunities for Pakistani businesses, exporters and young entrepreneurs. In a special gesture of friendship and goodwill, RCCI President Usman Shaukat and Rana Mashhood Ahmad Khan jointly presented H.E. Carlos Aragón Gil de la Serna with a football manufactured in Pakistan for the FIFA World Cup. The presentation showcased Pakistan’s strong sports manufacturing capabilities and symbolized the growing friendship, cooperation and people-to-people ties between Pakistan and Spain. The Spanish Ambassador also participated in RCCI’s Independence Day celebrations and cake-cutting ceremony, further reflecting the warm cultural and people-to-people relations between the two countries. The meeting concluded with a shared commitment to promoting bilateral trade and investment, technology cooperation, agricultural collaboration and stronger institutional linkages for the mutual economic benefit of Pakistan and Spain.

  • |

    Trump says US will maintain control of Strait of Hormuz 

      US President Donald Trump has said American forces are likely to remain in control of the strategically important Strait of Hormuz, as tensions between Washington and Tehran continue to rise and efforts to revive a temporary peace agreement show little progress. In a post on his Truth Social platform on Wednesday, Trump claimed that the United States has “total control” over the waterway and suggested that Washington intends to maintain its presence there. He described the ongoing naval blockade as a “wall of steel” and said Iran had no effective means of challenging it. Trump also claimed that Iran’s military strength had been severely weakened, alleging that the Islamic Revolutionary Guard Corps had been “decimated.” He further described Iran’s economy as collapsing, pointing to high inflation and accusing Tehran of relying on rhetoric rather than meaningful action. However, an Iranian source said there had been no progress in efforts to restore an interim agreement reached in June. The agreement had called for an immediate halt to military operations and provided a 60-day period, which could be extended by mutual agreement, for both sides to negotiate a longer-term settlement. The arrangement quickly deteriorated. Trump later declared the agreement over, while Iran described it as suspended. Tehran has accused Washington of failing to meet its commitments, including lifting restrictions on Iranian ports and releasing frozen Iranian financial assets. The United States, meanwhile, has accused Iran of failing to reopen the Strait of Hormuz. The Iranian source said mediators were discussing the possibility of Washington returning to the interim agreement and establishing a timetable for fulfilling its commitments, but no progress had been made. Tensions have increased further following fresh attacks on shipping in the region. The Strait of Hormuz, located between Iran and Oman, is one of the world’s most important energy routes and previously carried around one-fifth of global oil and liquefied natural gas supplies. Concerns over disruptions have contributed to a sharp rise in oil prices since the conflict began. Shipping traffic through the strait also dropped significantly. Data showed that only eight vessels were tracked passing through the waterway on Tuesday, the lowest daily figure in about a week. Ship operators have increasingly avoided the route because of security concerns. Additional attacks were reported at other major maritime chokepoints. In the Bab el-Mandeb Strait at the southern end of the Red Sea, four crew members were reportedly killed when an Iran-backed Houthi attack targeted a small cargo vessel. Two Yemeni rescuers were also reported killed. The US military separately said an American Navy helicopter fired two missiles to disable the steering system of a Panama-flagged cargo ship. US Central Command said the vessel had ignored repeated warnings and violated the naval blockade of Iranian ports. Maritime sources said the ship was struck near Pakistan while travelling toward the Gulf of Oman. The latest attacks have increased concerns about global energy supplies. Brent crude prices continued to rise, while investors reacted to growing uncertainty over the possibility of a quick end to the conflict. Iran has warned that the Strait of Hormuz will remain closed unless Washington accepts its conditions for ending the war. At the same time, Trump has continued to alternate between threatening further escalation and suggesting that a peace agreement could be reached soon. With military tensions, attacks on commercial shipping and diplomatic disagreements continuing, prospects for a swift resolution appear increasingly uncertain.

  • | |

    Pakistan information commission declares Pakistan …

    ISLAMABAD: The Pakistan Information Commission (PIC) has declared the Pakistan Bar Council (PBC) a public body under the Right of Access to Information Act, 2017, and directed it to provide within 15 days information sought regarding lawyers’ degrees, licence cancellations, government grants and governing body proceedings. The order was issued in appeal titled Saddia Mazhar vs Pakistan Bar Council, by Chief Information Commissioner Shoaib Ahmad Siddiqui and Information Commissioner Ijaz Hassan Awan. The applicant had sought eight categories of information, including province-wise numbers of PBC members or licence holders; those who had submitted attested degrees; lawyers whose licences were cancelled for failing to submit attested educational documents; and those whose licences were cancelled over fake degrees. She also sought copies of circulars and notifications concerning degree attestation, details of federal and provincial government grants received since 2020, including amounts and dates, and a copy of the latest minutes of the PBC Governing Body meeting. In its reply to the Commission, that the PBC maintained that it was an autonomous statutory body generating its own funds and did not fall within the definition of a public body. Its representatives argued that the government exercised neither financial nor administrative control over it, while acknowledging that the Attorney General for Pakistan is its ex officio member. The Commission rejected the PBC’s position, holding that it is a statutory organisation established under the Legal Practitioners and Bar Councils Act, 1973, and performs important public functions relating to legal education, recognition of law degrees and regulation of legal practitioners. It also observed that Bar Councils receive public funds or government grants and their offices are located in public buildings. The PIC ruled that the PBC falls within the definition of a public body under Section 2(ix)(g) and (h) of the Right of Access to Information Act, 2017. It further held that none of the eight information requests attracted an exemption under the law. The Secretary, Pakistan Bar Council, was consequently directed to provide the requested information within 15 days of receiving the order. The case was adjourned until September 2, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *