3 weeks ago

Hackers Target Major US Financial Firms in Credential Theft Campaign

Hackers Target Major US Financial Firms in Credential Theft Campaign
Hackers targeted Blackstone, CME and other major US financial firms in credential theft campaign: Report · firstpost.com

Some very sneaky people called hackers are tricking workers at big money companies in the United States.

They pretend to be the company's IT helper and say the worker must update their password or security settings right away.

Then they send the worker to a fake website that looks real, where the worker types in their username and password.

While the worker is talking on the phone, the hackers grab the secret one-time codes that are sent to their phone.

This lets the hackers get into company accounts very quickly, before the worker even realizes something is wrong.

The companies that were tricked include very famous money firms like Blackstone, CME, and Moody's.

The hackers did not even need fancy computer viruses; a simple phone call was enough to do the job.

Google, a big technology company, found out about these tricks and wrote a report to warn people.

These attacks remind us that even smart computers need people to be careful about who they trust on the phone.

Key facts

Targeted firms
Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Moody's
Attack method
Fake IT help-desk phone calls and spoofed credential-stealing websites
Hacker aliases
Redact, Pin, Falcon, Helix
Reported by
Google's Threat Intelligence Group; internet intelligence data reviewed by Reuters
Scope
Dozens of prominent US financial institutions and businesses compromised over the past month
Analyst
Austin Larsen, Principal Threat Analyst at Google's Threat Intelligence Group
Recent focus
Private equity firms, law firms, and financial ratings agencies
Related vulnerability example
CitrixBleed, with Boeing among the highest-profile known victims

Sources

Related news