Google's security researchers reported Thursday that hacker groups it dubbed Falcon, Helix, Pink and Redact are breaking into large US financial and investment firms to steal sensitive data and extort victims with threats of publication. The groups use voice phishing (vishing), calling employees on personal cellphones and pretending to be coworkers or IT helpdesk staff to trick them into entering credentials and multi-factor codes on spoofed websites. Reuters reported the victims may include firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater, CME Group, KKR, Moody's and TPG.
The unnamed firms are the latest targets of a well-established extortion tactic in which hackers publicise breaches on their own websites to pressure victims into paying ransoms. Even in an era of AI-powered autonomous attacks, Google noted that crude social-engineering techniques still produce strong results against high-value corporate targets.
The campaign shows that sophisticated, well-funded attackers continue to rely on simple human manipulation to breach some of the world's largest financial institutions, whose employees hold valuable, market-moving data. It also signals a growing threat of data-exfiltration extortion against the private financial sector.

Google's security researchers reported Thursday that hacker groups it dubbed Falcon, Helix, Pink and Redact are breaking into large US financial and investment firms to steal sensitive data and extort victims with threats of publication. The groups use voice phishing (vishing), calling employees on personal cellphones and pretending to be coworkers or IT helpdesk staff to trick them into entering credentials and multi-factor codes on spoofed websites. Reuters reported the victims may include firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater, CME Group, KKR, Moody's and TPG.

The unnamed firms are the latest targets of a well-established extortion tactic in which hackers publicise breaches on their own websites to pressure victims into paying ransoms. Even in an era of AI-powered autonomous attacks, Google noted that crude social-engineering techniques still produce strong results against high-value corporate targets.

The campaign shows that sophisticated, well-funded attackers continue to rely on simple human manipulation to breach some of the world's largest financial institutions, whose employees hold valuable, market-moving data. It also signals a growing threat of data-exfiltration extortion against the private financial sector.

πŸ“° Source: TechCrunch
techcrunch.com β†—
Was this article useful?