Techcrunch
Hackers Target Major US Financial Firms Using Phone-Based Phishing Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A coordinated hacking campaign has targeted numerous prominent US financial institutions, including Blackstone, CME Group, and Apollo Global Management, over the past month. Hackers employed social engineering tactics, specifically voice phishing (vishing), to deceive employees into providing login credentials and multi-factor authentication codes. The attackers impersonated IT helpdesk staff during phone calls, directing victims to fraudulent websites designed to capture sensitive information. Google identified the hacking groups under aliases such as Redact, Pink, Falcon, and Helix. The campaign appears financially motivated, with the potential for ransom demands based on the stolen data. While some companies may have paid ransoms, the exact number of successful breaches remains unclear. The use of low-tech methods highlights vulnerabilities in even the most sophisticated security systems. Google has warned that these tactics could lead to significant data breaches if not addressed.
Key Points: • Hackers targeted major US financial firms using voice phishing techniques. • Groups involved include Redact, Pink, Falcon, and Helix, focusing on sensitive data theft. • The campaign highlights vulnerabilities in security systems despite advanced protections.