Hackers target Wall Street firms in phone-based cy…
NEW YORK: Hackers seeking ransom have targeted dozens of major US financial institutions and businesses using a surprisingly simple tactic — posing as IT help desk employees and tricking staff into handing over passwords and authentication codes.
According to Google and internet intelligence data reviewed by Reuters, the campaign targeted prominent private equity and financial firms, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.
Google said the cybercriminals operate under several names, including Redact, Pink, Falcon and Helix. The technology giant said some companies targeted during the campaign had paid ransoms, although it did not identify those businesses. Reuters was also unable to determine which companies were successfully compromised.
The hackers reportedly created websites designed specifically for individual companies. Employees were then contacted by phone, sometimes through calls that appeared to originate from their organisation’s legitimate IT help desk.
The attackers allegedly told employees that they needed to urgently update their passkeys or multifactor authentication credentials. Victims were then directed to malicious websites using names designed to look legitimate, such as those containing phrases like “passkey helpdesk” or “secure passkey”.
Once an employee entered their credentials, the hackers could obtain an authentication code in real time, allowing them to take control of the account while remaining on the phone with the victim.
Austin Larsen, a principal threat analyst with Google’s Threat Intelligence Group, said the technique was not especially sophisticated but remained highly effective.
Cybersecurity experts said the campaign demonstrates that human behaviour remains one of the biggest vulnerabilities for even heavily protected organisations. Lee Clark of the Retail and Hospitality ISAC compared the tactic to persuading a security guard to open a heavily protected gate.
Google said the attackers had increasingly focused on private equity firms, law firms and financial ratings agencies because they may hold sensitive information that companies would be willing to protect through ransom payments.
Reuters identified 72 malicious websites listed in Google’s report and linked several of them to specific companies using internet intelligence platforms. Google cautioned that while the infrastructure indicated attempted intrusions, not every attack was necessarily successful.
The campaign appears to have affected a broader range of industries. Data reviewed by Reuters showed that hackers created digital traps targeting more than 200 companies during a five-week period, including Uber, Zillow and Levi Strauss, along with law firms such as Paul Hastings and Greenberg Traurig.
The hacking group’s shifting aliases have also complicated efforts to identify those behind the attacks. Google said the various names appeared connected through shared infrastructure, but acknowledged that important questions about the hackers’ identities and relationships remain unanswered.
The latest campaign has heightened concern across Wall Street, highlighting how convincing phone calls and basic social engineering can bypass sophisticated cybersecurity systems and expose highly valuable corporate accounts.