Hackers Target U.S. Financial Firms With Phone-Based Ransom Campaign
Ransom-seeking hackers have targeted dozens of prominent U.S. financial institutions and other businesses over the past month by combining phone calls with fake login websites to steal employee credentials. The campaign, identified by Google and supported by internet intelligence data reviewed by Reuters, highlights how simple social engineering techniques remain highly effective despite advances in cybersecurity.
The attackers created fraudulent websites designed to capture passwords from employees at private equity firms and financial companies. The targets included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s, alongside several other businesses.
Google said in a blog post that the hackers operate under several names, including Redact, Pink, Falcon and Helix. However, the company declined to comment on Reuters’ findings. Its report noted that some unnamed organisations paid ransoms following successful attacks. Reuters could not determine which companies, if any, had been compromised.
Financial Sector Faces Persistent Social Engineering Threats
Cybersecurity specialists say the campaign demonstrates that traditional deception techniques continue to succeed even as organisations invest heavily in advanced security systems and AI-driven defences.
Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, said attackers increasingly rely on manipulating people rather than defeating technical barriers.
According to Clark, modern security may be sophisticated, but convincing an employee to grant access remains one of the easiest ways to breach an organisation. He added that the human element continues to drive the success of such attacks.
Several companies named in the data declined to comment, including KKR, Bain Capital, Clearlake Capital, CME Group, TPG and Apollo. Meanwhile, Blackstone, Bridgewater Associates and Moody’s did not immediately respond to requests for comment.
Google Says Hackers Shifted Focus to Finance
Google said the group recently expanded its focus to private equity firms, law firms and financial ratings agencies.
Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, said the attackers choose industries based on financial incentives. He explained that organisations holding highly sensitive information are viewed as more likely to pay to prevent stolen data from becoming public.
Although Google did not identify specific targets, Reuters analysed the 72 malicious websites listed in Google’s report using web intelligence platforms. The analysis revealed customised malicious subdomains tailored to individual companies.
Larsen said the websites were likely used in attempted intrusions, although he stressed that not every attempt succeeded.
Google said the attackers relied on carefully planned social engineering. They contacted employees on personal mobile phones while pretending to represent their company’s IT help desk. In some cases, they even displayed legitimate help desk telephone numbers.
The callers claimed there was an urgent requirement to update passkeys or multifactor authentication. Employees were then directed to fraudulent websites using domains such as “passkeyhelpdesk” or “secure-passkey.”
If victims entered their credentials, the attackers captured both passwords and one-time authentication codes in real time before taking control of the accounts during the same phone call.
Larsen said the technique should not be viewed as highly sophisticated. Instead, he described it as a straightforward approach that continues to produce effective results.
Multiple Hacker Identities Create Uncertainty
Reuters was unable to contact the alleged hackers.
Redact, previously known as Blackfile, stated on its darknet website that its members were neither politically nor morally motivated and were not taking questions from the media. Falcon acknowledged an affiliation with Redact but denied any connection with Helix or Pink.
Larsen said the precise identities of the attackers and their relationships remain uncertain. Nevertheless, he noted that the different groups appear to share common infrastructure, suggesting some level of connection despite operating under separate names.
The campaign has attracted significant attention across Wall Street.
Point72 Asset Management informed investors that it had been targeted by hackers, according to a source familiar with the matter. Two sources also said the attackers attempted to breach other hedge funds, including Two Sigma Investments and Citadel, whose names appeared in the data reviewed by Reuters.
Two Sigma did not respond to requests for comment, while Citadel and Point72 declined to comment.
The reviewed data also showed that the hackers previously targeted more than 200 companies over the past five weeks before shifting their attention towards financial institutions.
Other organisations included Uber, Zillow, Levi Strauss and several law firms, including Paul Hastings and Greenberg Traurig.
Uber, Zillow, Paul Hastings and Levi Strauss did not respond to requests for comment. Greenberg Traurig said it had not experienced a data breach because of the security measures it has in place to protect client information, although it provided no additional details.
With inputs from Reuters

