Hackers use old-school phone scams to breach financial firms

1 hour ago 2



Hackers have launched a wave of phone-based phishing attacks against prominent US financial firms, relying on social engineering rather than technical exploits to breach corporate accounts. Google said the attackers, tracked under aliases including Redact, Pink, Falcon, and Helix, targeted private equity firms, financial services companies, law firms, and ratings agencies by posing as internal IT support staff. Employees were directed to fake passkey or multifactor authentication portals designed to capture login credentials and authentication codes during live phone calls. According to Reuters, dozens of malicious domains were linked to organizations including Blackstone, Apollo, Bain Capital, KKR, TPG, CME Group, Bridgewater Associates, and Moody’s. Google said the campaign appeared financially motivated, with attackers seeking access to sensitive corporate data that could be used to demand ransom payments. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article