Briev
Live
Business

Google warns of vishing scams targeting major US financial firms

Google's security team says unknown hackers are calling employees at large U.S. financial firms, posing as coworkers to steal credentials and extort data.

Google’s security researchers disclosed that a set of unidentified hackers are targeting large U.S. financial and investment firms by calling employees on personal phones and impersonating internal IT or colleagues. The callers aim to obtain usernames, passwords and multi-factor authentication codes, which victims enter on counterfeit websites, a tactic known as vishing. The groups, named Falcon, Helix, Pink and Redact, subsequently publish threats to leak the compromised data unless victims pay ransoms ranging from $750,000 to $3 million.

One outlet identified several of the affected firms as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG, though none commented. Google suspects the actors belong to a larger collective called UNC6671 and notes they have also targeted firms in manufacturing, real estate, healthcare, tech, transportation and hospitality. A cryptocurrency wallet tied to one of the groups collected about $10 million in Bitcoin in the first months of the year.

Why it matters

The scheme shows how simple phone scams can breach high-value financial institutions and lead to costly data extortion.

In this story

vishingvoice phishingcredential theftextortionfinancial firmsGoogle security reportcryptocurrency walletransom demandUNC6671