Google Unveils Sophisticated Phone-Based Phishing Campaign Targeting U.S. Firms
Google's threat intelligence team has uncovered a coordinated phone-based phishing campaign targeting major U.S. financial and investment firms.
The attackers, who have been assigned names by Google as Falcon, Helix, Pink, and Redact, are impersonating IT staff to steal employee credentials and multi-factor authentication codes through fake websites designed to capture corporate login information.
The campaign's focus on large financial organizations highlights the potential for significant leverage in extortion efforts. Victims are pressured to pay ransoms to prevent public exposure of stolen data.
Security experts warn that credential theft and extortion can be especially damaging for financial institutions due to the sensitive nature of client records, investment data, and internal communications.