Hackers Target Major U.S. Financial Firms Using Phone-Based Attacks
Ransom-seeking hackers have targeted several prominent U.S. financial institutions and businesses using phone calls to compromise their security. According to data reviewed by Reuters, these hackers have focused on private equity firms and financial companies, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. The hackers created websites designed to steal passwords from employees of these firms. Google, in a blog post, identified the hackers as operating under various names such as Redact, Pink, Falcon, and Helix. Despite the advanced security measures in place, these low-tech social engineering tactics have proven effective. Some companies have reportedly paid ransoms, although it is unclear which firms were successfully compromised.