Close Menu
Stratnews GlobalStratnews Global
    Facebook X (Twitter) Instagram
    Trending
    • 9/11@25: How Terrorism Reshaped Global Geopolitics
    • The Indian Economy Keeps Beating Expectations
    • Going Green Can Make India More Competitive
    • NEET: Why People Game The System?
    • Social Media Bans Expand For Children Worldwide
    • Perplexity Valuation Could Exceed $30 Billion
    • Vatican Renewable Energy Plant To Power Holy See
    • Terrier Cyber Quest 2026 Opens National Hackathon
    • Support Us
    Stratnews GlobalStratnews Global
    Write for Us
    Friday, September 18
    • Space
    • Science
    • AI and Robotics
    • Industry News
    • Support Us
    Stratnews GlobalStratnews Global
    Home » Phone-Based Hackers Target U.S. Financial Firms

    Phone-Based Hackers Target U.S. Financial Firms

    Aditya LenkaBy Aditya LenkaAugust 7, 2026 World No Comments4 Mins Read
    Phone-based hackers

    Hackers Target U.S. Financial Firms With Phone-Based Ransom Campaign

    Ransom-seeking hackers have targeted dozens of prominent U.S. financial institutions and other businesses over the past month by combining phone calls with fake login websites to steal employee credentials. The campaign, identified by Google and supported by internet intelligence data reviewed by Reuters, highlights how simple social engineering techniques remain highly effective despite advances in cybersecurity.

    The attackers created fraudulent websites designed to capture passwords from employees at private equity firms and financial companies. The targets included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s, alongside several other businesses.

    Google said in a blog post that the hackers operate under several names, including Redact, Pink, Falcon and Helix. However, the company declined to comment on Reuters’ findings. Its report noted that some unnamed organisations paid ransoms following successful attacks. Reuters could not determine which companies, if any, had been compromised.

    Financial Sector Faces Persistent Social Engineering Threats

    Cybersecurity specialists say the campaign demonstrates that traditional deception techniques continue to succeed even as organisations invest heavily in advanced security systems and AI-driven defences.

    Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, said attackers increasingly rely on manipulating people rather than defeating technical barriers.

    According to Clark, modern security may be sophisticated, but convincing an employee to grant access remains one of the easiest ways to breach an organisation. He added that the human element continues to drive the success of such attacks.

    Several companies named in the data declined to comment, including KKR, Bain Capital, Clearlake Capital, CME Group, TPG and Apollo. Meanwhile, Blackstone, Bridgewater Associates and Moody’s did not immediately respond to requests for comment.

    Google Says Hackers Shifted Focus to Finance

    Google said the group recently expanded its focus to private equity firms, law firms and financial ratings agencies.

    Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, said the attackers choose industries based on financial incentives. He explained that organisations holding highly sensitive information are viewed as more likely to pay to prevent stolen data from becoming public.

    Although Google did not identify specific targets, Reuters analysed the 72 malicious websites listed in Google’s report using web intelligence platforms. The analysis revealed customised malicious subdomains tailored to individual companies.

    Larsen said the websites were likely used in attempted intrusions, although he stressed that not every attempt succeeded.

    Google said the attackers relied on carefully planned social engineering. They contacted employees on personal mobile phones while pretending to represent their company’s IT help desk. In some cases, they even displayed legitimate help desk telephone numbers.

    The callers claimed there was an urgent requirement to update passkeys or multifactor authentication. Employees were then directed to fraudulent websites using domains such as “passkeyhelpdesk” or “secure-passkey.”

    If victims entered their credentials, the attackers captured both passwords and one-time authentication codes in real time before taking control of the accounts during the same phone call.

    Larsen said the technique should not be viewed as highly sophisticated. Instead, he described it as a straightforward approach that continues to produce effective results.

    Multiple Hacker Identities Create Uncertainty

    Reuters was unable to contact the alleged hackers.

    Redact, previously known as Blackfile, stated on its darknet website that its members were neither politically nor morally motivated and were not taking questions from the media. Falcon acknowledged an affiliation with Redact but denied any connection with Helix or Pink.

    Larsen said the precise identities of the attackers and their relationships remain uncertain. Nevertheless, he noted that the different groups appear to share common infrastructure, suggesting some level of connection despite operating under separate names.

    The campaign has attracted significant attention across Wall Street.

    Point72 Asset Management informed investors that it had been targeted by hackers, according to a source familiar with the matter. Two sources also said the attackers attempted to breach other hedge funds, including Two Sigma Investments and Citadel, whose names appeared in the data reviewed by Reuters.

    Two Sigma did not respond to requests for comment, while Citadel and Point72 declined to comment.

    The reviewed data also showed that the hackers previously targeted more than 200 companies over the past five weeks before shifting their attention towards financial institutions.

    Other organisations included Uber, Zillow, Levi Strauss and several law firms, including Paul Hastings and Greenberg Traurig.

    Uber, Zillow, Paul Hastings and Levi Strauss did not respond to requests for comment. Greenberg Traurig said it had not experienced a data breach because of the security measures it has in place to protect client information, although it provided no additional details.

    With inputs from Reuters

    Author

    • Aditya Lenka
      Aditya Lenka

      A multi-faceted professional with a diverse range of skills and experiences. He currently works as a Producer, Digital Marketer, and Journalist for several well-known media outlets, namely StratNewsGlobal, BharatShakti, and Interstellar. With a passion for storytelling and a keen eye for detail, Aditya has covered a wide range of topics and events across India, bringing a unique perspective to his work.

      When he's not busy producing content, Aditya enjoys exploring new places and cuisines, having traveled extensively throughout India. He's also an avid writer and poet, often penning his thoughts and musings in his free time. And when he wants to unwind and relax, Aditya spends time with his two loyal companions, Zorro and Pablo, his beloved dogs.

      Aditya's dynamic personality and varied interests make him a unique individual, always eager to learn and experience new things.

      View all posts
    Cyber Featured Industry US
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Reddit Telegram WhatsApp
    Aditya Lenka
    Aditya Lenka

      A multi-faceted professional with a diverse range of skills and experiences. He currently works as a Producer, Digital Marketer, and Journalist for several well-known media outlets, namely StratNewsGlobal, BharatShakti, and Interstellar. With a passion for storytelling and a keen eye for detail, Aditya has covered a wide range of topics and events across India, bringing a unique perspective to his work.When he's not busy producing content, Aditya enjoys exploring new places and cuisines, having traveled extensively throughout India. He's also an avid writer and poet, often penning his thoughts and musings in his free time. And when he wants to unwind and relax, Aditya spends time with his two loyal companions, Zorro and Pablo, his beloved dogs.Aditya's dynamic personality and varied interests make him a unique individual, always eager to learn and experience new things.

      Keep Reading

      Going Green Can Make India More Competitive

      Social Media Bans Expand For Children Worldwide

      Perplexity Valuation Could Exceed $30 Billion

      Vatican Renewable Energy Plant To Power Holy See

      Terrier Cyber Quest 2026 Opens National Hackathon

      Firebase Banking Scams Prompt India Action Against Google

      Add A Comment
      Leave A Reply Cancel Reply

      Anti Drone System (CUAS)
      Latest Posts

      9/11@25: How Terrorism Reshaped Global Geopolitics

      September 17, 2026

      The Indian Economy Keeps Beating Expectations

      September 10, 2026

      Going Green Can Make India More Competitive

      September 3, 2026

      NEET: Why People Game The System?

      August 27, 2026

      Social Media Bans Expand For Children Worldwide

      August 24, 2026

      Perplexity Valuation Could Exceed $30 Billion

      August 24, 2026

      Vatican Renewable Energy Plant To Power Holy See

      August 22, 2026

      Terrier Cyber Quest 2026 Opens National Hackathon

      August 21, 2026

      Firebase Banking Scams Prompt India Action Against Google

      August 21, 2026

      China Indonesia Energy Technology Cooperation Expands

      August 21, 2026

      Subscribe to News

      Get the latest sports news from NewsSite about world, sports and politics.

      • Astronomical Events
      • Space Missions
      • Industry News
      • Science
      StratNewsGlobal Tech
      Facebook X (Twitter) Instagram LinkedIn YouTube
      © 2026 StratNews Global, A unit of BharatShakti Communications LLP
      • About Us
      • Contributors
      • Copyright
      • Contact
      • Write for Us

      Type above and press Enter to search. Press Esc to cancel.