Business / news
Google warns of vishing attacks targeting US financial firms
Google's security researchers have identified four hacking groups—Falcon, Helix, Pink, and Redact—that are targeting large financial and investment firms in the United States. In a report published Thursday, the researchers said the groups are using voice phishing, or vishing, to breach corporate networks.
The attackers place calls to employees' personal cellphones, posing as co-workers or IT helpdesk staff. They then direct victims to spoofed login pages designed to capture credentials and multi-factor authentication codes. Google said this old-fashioned method is still succeeding despite advances in AI-powered cyberattacks.
The companies compromised were not named by Google. However, other reporting has identified Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG as among the victims. These firms are leading players in private equity, investment management, and financial infrastructure.
The goal is data theft and extortion. The hackers steal sensitive information and threaten to publish it unless a ransom is paid. Some groups run websites that publicize hacked data to increase pressure on victims, a tactic common among cybercriminal gangs.