Hacking Groups Target Financial Firms with Voice Phishing Scams
Google researchers have identified four hacking groups targeting large financial and investment firms in the United States. These groups, known as Falcon, Helix, Pink, and Redact, are using an old-fashioned technique called voice phishing or vishing to trick employees into revealing sensitive information.
The hackers make phone calls to employees' personal cellphones, pretending to be coworkers or IT helpdesk staff, in order to obtain login credentials and multi-factor codes. They then use these details to gain access to the companies' systems and steal valuable data.
Once they have stolen the data, the hackers threaten to publish it unless a ransom is paid. According to Google, one cryptocurrency wallet associated with one of the hacking groups received around $10 million in Bitcoin in the first few months of this year. The hackers typically demand between $750,000 and $3 million from their victims.
The affected companies include leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG. Google believes that the hacking groups may all be part of a larger umbrella collective tracked under the name UNC6671.