Hackers Ran a Five-Week Phone-Call Campaign Against Blackstone, KKR and Dozens of Other Wall Street Firms
Google's Threat Intelligence Group disclosed Thursday that hackers spent weeks calling employees at major Wall Street firms, posing as IT help desk staff to steal login credentials.

For about the past month, a coordinated network of hacking groups has been calling employees at major U.S. private equity firms, hedge funds, and financial institutions, posing as internal IT help desk staff to steal login credentials.
Google Threat Intelligence Group disclosed the campaign Thursday without naming victims, but Reuters matched Google’s findings with internet intelligence data to identify targets including Blackstone, KKR, Apollo Global Management, and CME Group.
Separately, reports also note that Citadel, Point72, and Two Sigma were also targeted, citing people familiar with the incidents.
An Old Trick Beating Modern Security Budgets
According to Google Threat Intelligence, the hackers directed employees to fake login pages designed to steal passwords and multi-factor authentication codes in real time.
The tactic works because it deceives the employees rather than breaking through the company’s technical security defenses.
Reuters also cited Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality ISAC, who said modern security systems are so strong that attackers often find it easier to trick employees than hack the systems themselves.
The campaign also exposes a wider gap in cybersecurity spending.
While financial firms have invested heavily in firewalls, endpoint detection, and encryption, attackers still bypassed those defenses with a phone call and a convincing script, exposing how much more companies invest in technology than employee training.
From Manufacturing to Wall Street’s Inner Circle
Google’s report shows the hackers deliberately changed targets over time, moving from manufacturing, real estate, healthcare, and hospitality to legal and financial firms.
Researchers said the shift was likely intended to target more valuable information, as private equity firms hold sensitive details on mergers, acquisitions, and investments that can be used for extortion.
Fortune reported a similar trend on Wall Street, quoting Align Managed Services president Vinod Paul, who said AI has allowed attackers to scale campaigns from targeting about 50 organisations to as many as 1,000.
He added that voice cloning technology also makes impersonation calls far more convincing.
A Reminder That Scale, Not Sophistication, Is the New Threat
For an industry that has spent heavily on securing networks and encrypting data at rest, the more uncomfortable lesson from this month may be that the weakest link was never the software; it was the assumption that a familiar voice on a familiar phone number could be trusted at all.
What makes this campaign stand out isn’t the technique itself. Vishing has been around for years. It’s the scale.
Reuters, citing internet intelligence data, said the attackers targeted more than 200 organisations in about five weeks, including private equity firms, hedge funds, law firms, and consumer technology companies such as Uber and Zillow.
That suggests the real change isn’t a new hacking method but the use of AI and automation to carry out an old scam on a much larger scale.
For an industry that has invested heavily in upgrading security networks and data encryption, the bigger lesson is that technology wasn’t the weakest link.
It was the trust employees placed in what sounded like a legitimate call from their own IT department.
Source: Hackers targeted US private equity, other firms including Blackstone, CME, data shows



![Top Tech Stories of 9th Week [2026]](https://www.nogentech.org/wp-content/uploads/2026/03/Top-Tech-Stories-of-9th-Week-2026-390x220.webp)