Site icon Pashto News and Current Affairs Channel | Khyber News

Hackers Target Financial Firms via Phone Scams

A wave of ransom-driven cyberattacks has hit dozens of major American financial institutions and corporations over the past month, according to intelligence data from Google reviewed by Reuters. The attackers relied on phone-based social engineering methods rather than traditional hacking tools to trick employees into giving up their login credentials.

Among the firms whose staff were targeted are some of the biggest names in private equity and finance, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody’s. The attackers reportedly built convincing fake login pages designed to harvest passwords from unsuspecting employees.

How the Group Behind the Attacks Operates

Google identified the perpetrators as a hacking group that goes by several names, including Redact, Pink, Falcon and Helix. In a blog post detailing its findings, the tech giant confirmed that some organizations affected by the breaches had already paid ransoms to the attackers, though it stopped short of naming which companies had done so.

Reuters noted it was unable to independently confirm exactly which firms had actually been compromised in the campaign.

Old-School Tactics Still Prove Effective

Security analysts say the incident is a reminder that even basic techniques like phone calls remain surprisingly effective, even as companies invest heavily in AI-driven threat detection and other advanced cybersecurity tools.

Lee Clark, who serves as a cyberthreat intelligence manager at the Retail and Hospitality Information Sharing and Analysis Center, pointed out that attackers are increasingly choosing to exploit human behavior instead of trying to break through hardened digital defenses.

When approached for comment, several of the named companies, including KKR, Bain Capital, CME Group, TPG and Apollo, declined to respond. Blackstone, Bridgewater Associates and Moody’s had not issued any response at the time of reporting.

Exit mobile version