
Hackers have launched a sophisticated ransom campaign targeting major US financial and professional services companies, according to reports from Reuters. The attackers have specifically targeted Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's, highlighting the vulnerability of organisations that hold valuable financial and corporate information. Google's threat intelligence team identified 72 malicious web addresses linked to the campaign, with internet intelligence services identifying subdomains created to resemble the targeted organisations. As per Google's latest blog post, the hackers have been operating over the past month, putting private equity groups, exchanges and ratings firms at risk by exploiting employees rather than breaking through technical defenses. The campaign has recently expanded its focus to private equity firms, law practices and credit-rating agencies, demonstrating the broad scope of the targeted sectors.
The attackers have operated under several names including Redact, Pink, Falcon and Helix, as reported by Reuters. Their approach relies heavily on social engineering, with attackers contacting employees through personal phones while posing as internal IT or help-desk personnel. The callers claim an urgent security update is required and direct employees to fake websites designed to capture passwords and authentication information. According to Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, the attackers select organisations where stolen information could potentially generate substantial ransom payments. Google reports that the hackers contact employees on personal cellphones while posing as company help desk staff, sometimes displaying the correct help desk number, and direct workers to fake websites such as "passkeyhelpdesk" or "secure-passkey" to persuade them to update passkeys or multifactor authentication. If an employee followed the instructions to enter their password, the hackers would harvest their fail-safe passcode – typically sent by text or generated by an app – live over the phone and hijack their account before the call terminated.
The attackers can obtain one-time verification codes, including those generated by authentication applications or delivered through text messages, allowing them to seize control of accounts during the call, as reported by Reuters. According to Google's latest report, the hackers use adversary-in-the-middle (AiTM) systems to intercept credentials and multi-factor authentication tokens once victims are directed to spoofed login portals. Once inside, the attackers run automated scripts to pull data from cloud services like Microsoft 365 and Okta. Some unnamed organisations paid ransoms, although it was not clear which companies were successfully breached. Google's blog post indicates that in some cases, companies paid ransoms to the hackers, though the specific targets were not named. The campaign's effectiveness demonstrates how sophisticated security programs and AI-driven threats have made traditional social engineering tactics even more potent against financial sector targets.
The hacking attempts have caused significant concern on Wall Street, with Point72 Asset Management telling investors on Wednesday that it had been targeted by hackers, according to sources familiar with the matter. As reported by Reuters, the hackers also attempted to breach other hedge funds, including Two Sigma Investments and Citadel, whose names appeared in the data reviewed by Reuters. However, Two Sigma and Point72 have not returned messages seeking comment, while Citadel declined to comment. The data shows the cybercriminals built digital traps for more than 200 companies in the past five weeks alone, including ride-hailing company Uber, online broker Zillow, jeans brand Levi Strauss, and several law firms including Paul Hastings and Greenberg Traurig. Google's latest report reveals that UNC6671, the group behind these attacks, shifted its focus over the summer. Through June, the group leaned toward technology, transport, and hospitality names, chasing trade secrets, code, and client data. The following month, it turned to money and law, with the group's infrastructure pointed at private equity firms, law firms, and financial rating agencies.