Financial firms cyberattacks squeeze $10M in bitcoin via fake IT calls

3 hours ago 20
financial firms cyberattacks

A phone call from “IT support” is turning into one of the most costly social-engineering threats facing Wall Street right now. According to a new Google security report, a wave of coordinated financial firms cyberattacks has hit some of the largest private equity and investment firms in the United States, with hackers using old-fashioned phone calls rather than sophisticated malware to break into corporate networks and steal sensitive data for extortion.

Key takeaways

  • Google identified four hacking groups — Falcon, Helix, Pink, and Redact — using voice phishing calls to breach US financial firms.
  • Targets reportedly include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG, per Reuters.
  • Google tracks the activity under a broader collective called UNC6671, though it’s unclear if the groups are affiliates or independent operators.
  • Ransom demands typically range from $750,000 to $3 million, and one wallet tied to the campaign received roughly $10 million in bitcoin this year.

Voice Phishing Attacks Targeting US Financial Firms

Unknown hackers are breaking into large financial and investment firms across the country with one clear goal: stealing sensitive corporate data they can later use to extort victims by threatening to publish it. Google’s security researchers detailed the campaign in a report published Thursday, describing a pattern of attacks that leans on human error rather than software exploits.

The technique at the center of this campaign is known in the industry as voice phishing, or vishing. It’s a decades-old con dressed up for a modern corporate environment, and it appears to be working well against employees who assume a phone call is safer than a suspicious email.

Impersonation Techniques Used in Vishing

The attackers call employees’ personal cellphones and pose as co-workers or internal IT helpdesk staff. During these calls, they try to walk the target through entering login credentials and multi-factor authentication codes on websites built to look like legitimate company portals. Once those credentials land in the wrong hands, the hackers gain the access they need to move deeper into a firm’s systems.

This matters because multi-factor authentication is widely treated as a security safety net. When someone is talked into typing a one-time code into a fake page in real time, that safety net effectively disappears — no firewall or antivirus tool can stop a decision made by a trusting employee on the phone.

Key Financial Firms Affected

Google did not publicly name any victims in its report. Reuters, however, reported that the list of targeted organizations includes several of the biggest names in private equity and financial services: Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. Laurie Bischel, a spokesperson for CME Group, declined to comment when asked about the reporting. Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s, and TPG did not respond to requests for comment.

Extortion Strategies and Financial Demands

Once inside a network, the hackers don’t just steal data quietly — several of the groups run public-facing extortion sites designed to pressure victims into paying up fast. This is a well-worn tactic among cybercriminal outfits, but its use against elite financial institutions raises the stakes considerably given the sensitivity of deal-related information these firms hold.

Public Extortion Websites and Threats

According to Google, some of the identified groups operate dedicated leak sites where they publicize breaches and threaten to release stolen files unless a ransom is paid. One of those sites carried language framing the extortion almost like a business negotiation: “We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” the message read, adding, “Respond promptly and in good faith, and the matter is resolved without further incident.”

Ransom Demands and Cryptocurrency Payments

The money involved is substantial. Google’s researchers said the hackers typically demand between $750,000 and $3 million from each victim. In one striking data point, a cryptocurrency wallet linked to one of the hacking groups received around $10 million in bitcoin during the first few months of this year alone — a figure that suggests the campaign has already paid off handsomely for whoever is behind it.

Coordination Among Hacking Groups Under UNC6671

Google’s researchers believe the four named groups may not be operating in isolation. Instead, they could be different faces of a single, larger network designed to obscure the true scale of the operation.

Identified Hacking Groups and Possible Affiliations

Google dubbed the four groups Falcon, Helix, Pink, and Redact, and says they may all fall under a broader umbrella the company tracks internally as UNC6671. What remains unclear is the exact relationship between them — whether they are formal affiliates, splinter groups that broke off from a shared origin, or simply separate operators leaning on the same phishing-as-a-service infrastructure. “We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” Google’s report stated.

Strategic Motivations and Target Selection

This isn’t a campaign that started with private equity. Google says the same groups have previously gone after large companies in manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality, chasing “valuable intellectual property, software source code, or sensitive VIP client data.”

The pivot toward legal and financial organizations, including private equity firms, appears deliberate. Google’s researchers noted that “concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands.” In other words, the hackers seem to be chasing the kind of information — deal terms, litigation strategy, sensitive client records — that firms will pay handsomely to keep out of public view.

For an industry built on confidentiality and trust, that targeting logic is the real warning sign here. It’s not just about one breach or one payout; it’s a signal that attackers have identified private equity and financial services as fertile ground precisely because the cost of exposure, for these firms, is so much higher than the ransom itself.

FAQ

How do hackers gain access to employees’ credentials in these attacks?

Hackers make phone calls impersonating co-workers or IT helpdesk staff to trick employees into entering credentials on spoofed websites.

What financial firms have been targeted in these voice phishing attacks?

Targeted firms reportedly include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.

What extortion tactics do the hackers use after stealing data?

Some groups run websites that threaten to publish stolen data unless victims pay ransoms.

What are the typical ransom demands made by these hacker groups?

The ransom demands typically range between $750,000 and $3 million.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article