Hackers Target Major US Financial Firms Using Phone-Based Phishing Attacks

Hackers Target Major US Financial Firms Using Phone-Based Phishing Attacks

First seen 6 Aug 2026, 23:23 UTC CryptobriefingTechcrunchItnews.Aucloud.google.com 87% similarity 66.5

Article Content

Browse articles
ThreatCluster

A coordinated hacking campaign has targeted numerous prominent US financial institutions, including Blackstone, CME Group, and Apollo Global Management, over the past month. Hackers employed social engineering tactics, specifically voice phishing (vishing), to deceive employees into providing login credentials and multi-factor authentication codes. The attackers impersonated IT helpdesk staff during phone calls, directing victims to fraudulent websites designed to capture sensitive information. Google identified the hacking groups under aliases such as Redact, Pink, Falcon, and Helix. The campaign appears financially motivated, with the potential for ransom demands based on the stolen data. While some companies may have paid ransoms, the exact number of successful breaches remains unclear. The use of low-tech methods highlights vulnerabilities in even the most sophisticated security systems. Google has warned that these tactics could lead to significant data breaches if not addressed.

Key Points: • Hackers targeted major US financial firms using voice phishing techniques. • Groups involved include Redact, Pink, Falcon, and Helix, focusing on sensitive data theft. • The campaign highlights vulnerabilities in security systems despite advanced protections.

ThreatCluster AI How this analysis works

Timeline

2026-08-06
Google reports on hacking campaign
Google disclosed that hackers targeted financial firms using phone calls and fake websites to steal credentials.
Techcrunch
2026-08-06
Hacking groups identified
The groups involved in the attacks were identified as Redact, Pink, Falcon, and Helix, targeting private equity and financial firms.
Itnews.Au
Recent
Social engineering tactics used
Hackers employed voice phishing to trick employees into providing sensitive information during phone calls.
Cryptobriefing

Community

Browse all →