3 weeks ago
Hackers Target Major US Financial Firms in Credential Theft Campaign
Some very sneaky people called hackers are tricking workers at big money companies in the United States.
They pretend to be the company's IT helper and say the worker must update their password or security settings right away.
Then they send the worker to a fake website that looks real, where the worker types in their username and password.
While the worker is talking on the phone, the hackers grab the secret one-time codes that are sent to their phone.
This lets the hackers get into company accounts very quickly, before the worker even realizes something is wrong.
The companies that were tricked include very famous money firms like Blackstone, CME, and Moody's.
The hackers did not even need fancy computer viruses; a simple phone call was enough to do the job.
Google, a big technology company, found out about these tricks and wrote a report to warn people.
These attacks remind us that even smart computers need people to be careful about who they trust on the phone.
Ransom-seeking hackers compromised dozens of prominent US financial institutions and businesses over the past month, according to internet intelligence data reviewed by Reuters.
Targeted firms included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, and Moody's.
Attackers used fake IT help-desk phone calls and spoofed credential-stealing websites to capture employee usernames, passwords, and one-time passcodes.
Google said the hackers operated under several aliases, including Redact, Pin, Falcon, and Helix.
The campaign highlights that low-tech tactics such as phone calls remain highly effective despite advances in cybersecurity and AI-powered threats.
- Who
- Hackers operating under aliases including Redact, Pin, Falcon, and Helix, reported on by Google's Threat Intelligence Group and analyzed by Principal Threat Analyst Austin Larsen.
- What
- A credential theft campaign using phone-based social engineering, fake IT help-desk calls, and spoofed websites to steal employee credentials and one-time passcodes.
- Where
- United States, targeting major financial institutions and businesses.
- When
- Over the past month, with Google publishing its report on Thursday.
- Why
- Financial incentives, as the attackers choose industries based on financial gain and have often been successful.
Key facts
- Targeted firms
- Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Moody's
- Attack method
- Fake IT help-desk phone calls and spoofed credential-stealing websites
- Hacker aliases
- Redact, Pin, Falcon, Helix
- Reported by
- Google's Threat Intelligence Group; internet intelligence data reviewed by Reuters
- Scope
- Dozens of prominent US financial institutions and businesses compromised over the past month
- Analyst
- Austin Larsen, Principal Threat Analyst at Google's Threat Intelligence Group
- Recent focus
- Private equity firms, law firms, and financial ratings agencies
- Related vulnerability example
- CitrixBleed, with Boeing among the highest-profile known victims










