Cyber security NewsNews

Hackers Ran a Five-Week Phone-Call Campaign Against Blackstone, KKR and Dozens of Other Wall Street Firms

Google's Threat Intelligence Group disclosed Thursday that hackers spent weeks calling employees at major Wall Street firms, posing as IT help desk staff to steal login credentials.

Key Takeaways

  • Google identified four hacking groups, dubbed Falcon, Helix, Pink, and Redact, that it believes operate under a shared umbrella it tracks as UNC6671, likely to compartmentalize operations and isolate negotiation fallout.
  • The hackers use voice phishing, calling employees’ personal cellphones while impersonating help desk staff, sometimes spoofing the correct internal phone number to appear legitimate.
  • Google says attackers shifted toward financial firms holding valuable merger, acquisition, and investment data.
  • AI, voice cloning, and automation helped scale vishing attacks across more than 200 organisations in five weeks.

For about the past month, a coordinated network of hacking groups has been calling employees at major U.S. private equity firms, hedge funds, and financial institutions, posing as internal IT help desk staff to steal login credentials.

Google Threat Intelligence Group disclosed the campaign Thursday without naming victims, but Reuters matched Google’s findings with internet intelligence data to identify targets including Blackstone, KKR, Apollo Global Management, and CME Group.

Separately, reports also note that Citadel, Point72, and Two Sigma were also targeted, citing people familiar with the incidents.

An Old Trick Beating Modern Security Budgets

According to Google Threat Intelligence, the hackers directed employees to fake login pages designed to steal passwords and multi-factor authentication codes in real time. 

The tactic works because it deceives the employees rather than breaking through the company’s technical security defenses. 

Reuters also cited Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality ISAC, who said modern security systems are so strong that attackers often find it easier to trick employees than hack the systems themselves. 

The campaign also exposes a wider gap in cybersecurity spending. 

While financial firms have invested heavily in firewalls, endpoint detection, and encryption, attackers still bypassed those defenses with a phone call and a convincing script, exposing how much more companies invest in technology than employee training

From Manufacturing to Wall Street’s Inner Circle

Google’s report shows the hackers deliberately changed targets over time, moving from manufacturing, real estate, healthcare, and hospitality to legal and financial firms. 

Researchers said the shift was likely intended to target more valuable information, as private equity firms hold sensitive details on mergers, acquisitions, and investments that can be used for extortion. 

Fortune reported a similar trend on Wall Street, quoting Align Managed Services president Vinod Paul, who said AI has allowed attackers to scale campaigns from targeting about 50 organisations to as many as 1,000. 

He added that voice cloning technology also makes impersonation calls far more convincing.

A Reminder That Scale, Not Sophistication, Is the New Threat

For an industry that has spent heavily on securing networks and encrypting data at rest, the more uncomfortable lesson from this month may be that the weakest link was never the software; it was the assumption that a familiar voice on a familiar phone number could be trusted at all.

What makes this campaign stand out isn’t the technique itself. Vishing has been around for years. It’s the scale. 

Reuters, citing internet intelligence data, said the attackers targeted more than 200 organisations in about five weeks, including private equity firms, hedge funds, law firms, and consumer technology companies such as Uber and Zillow.

That suggests the real change isn’t a new hacking method but the use of AI and automation to carry out an old scam on a much larger scale.

For an industry that has invested heavily in upgrading security networks and data encryption, the bigger lesson is that technology wasn’t the weakest link. 

It was the trust employees placed in what sounded like a legitimate call from their own IT department.

Source: Hackers targeted US private equity, other firms including Blackstone, CME, data shows 

Fawad Malik

Fawad Malik is a digital marketing professional and technology writer with over 15 years of industry experience. He specializes in SEO, SaaS, AI, consumer technology, internet services, and content strategy. He is the Founder and CEO of WebTech Solutions, a digital agency focused on helping businesses grow through modern online strategies. Through NogenTech, Fawad shares practical insights on internet technology, WiFi, apps, AI tools, digital trends, and the latest tech updates for readers worldwide.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button