WASHINGTON (Web Desk) - Ransom-seeking hackers have targeted dozens of prominent US financial institutions and businesses over the past month using phone-based social engineering tactics designed to steal employee credentials, according to Google and internet intelligence data reviewed by Reuters.
The campaign reportedly targeted employees at leading private equity firms and financial companies, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's through fake websites created to capture passwords.
Google said the hacking group operates under multiple aliases, including Redact, Pink, Falcon and Helix. In a blog post, the company revealed that some unidentified organisations had paid ransoms following successful attacks, although it did not disclose the victims' identities.
Reuters said it could not independently verify which companies had been successfully compromised.
Cybersecurity experts said the campaign highlights the continued effectiveness of low-tech social engineering methods, such as phone calls, despite major advances in cybersecurity and artificial intelligence-based threat detection.
Lee Clark, a cyberthreat intelligence manager at the Retail and Hospitality Information Sharing and Analysis Center (ISAC), said attackers increasingly rely on manipulating people rather than bypassing sophisticated digital security systems.
Several companies named in the report, including KKR, Bain Capital, CME Group, TPG and Apollo, declined to comment, while Blackstone, Bridgewater Associates and Moody's did not immediately respond to requests for comment.