Finance

Hackers Targeted US Private Equity and Other Firms Including Blackstone and CME, Data Shows

0

The most effective hack this year isn’t a piece of AI-crafted malware or a zero-day exploit. It’s a phone call. Over the past month, ransom-seeking hackers who work the phones have gone after dozens of prominent U.S. financial institutions and other businesses, according to Google and internet intelligence data reviewed by Reuters. The targets read like a who’s who of Wall Street, and the method behind the campaign is almost insultingly simple.

Who was in the crosshairs

The data shows the hackers built websites designed to steal passwords from employees at private equity firms and financial companies including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among others. Google, in a blog post published Thursday, said the group operates under a rotating set of names including Redact, Pink, Falcon, and Helix, and that some companies it declined to identify had paid ransoms. Reuters could not confirm which firms were actually compromised.

Most of the named companies either declined to comment or didn’t respond. The scale, though, is hard to wave off. According to Google and the underlying data, the hackers laid digital traps for more than 200 companies in just the past five weeks, and the list stretches well beyond finance to Uber, Zillow, Levi Strauss, and law firms including Paul Hastings and Greenberg Traurig. Greenberg Traurig said its security protocols meant it had not suffered a breach, without elaborating.

The low-tech trick that keeps working

Here’s the uncomfortable part for an industry that spends fortunes on security. The hackers didn’t break the fence, they talked their way through the gate. As one cyberthreat analyst put it, when the fence gets high-tech enough, the move is simply to trick the guard into opening the door, and that human element is what keeps making this work.

The playbook was patient and specific. Google said the hackers used meticulous social engineering, reaching employees on personal cellphones while posing as the company help desk, sometimes even spoofing the correct help desk number on the caller ID. They’d tell the target that IT had issued an urgent order to update their passkeys or multifactor authentication, then steer them to a booby-trapped site with a name like “passkeyhelpdesk” or “secure-passkey.” If the employee entered a password, the hackers harvested the one-time passcode live over the phone and hijacked the account before the call even ended.

Google’s principal threat analyst, Austin Larsen, was blunt about how to categorize it. Sophisticated, he said, isn’t the right word. It’s just really effective. That distinction matters, because it means the defense isn’t a better firewall, it’s a workforce trained to hang up and call back.

Why this rattled Wall Street

The reason the finance sector got singled out comes down to cold math. Larsen said the group picks industries based on financial calculations, betting that firms holding sensitive enough data will pay to keep it from leaking. Private equity, law firms, and ratings agencies fit that profile neatly, which is exactly where Google said the hackers had recently turned their focus.

The unease has spread fast. Point72 Asset Management told investors on Wednesday it had been targeted, and sources said the hackers also tried to breach other hedge funds, including Two Sigma and Citadel, both of which appeared in the data. Citadel and Point72 declined to comment.

Who’s actually behind it remains murky. Reuters couldn’t reach the alleged hackers, and while they operate under different aliases, Larsen said they appear linked by shared infrastructure rather than any clear single identity. Redact, formerly known as Blackfile, claimed on its darknet site to have no political or moral motive and said it wasn’t taking press questions. So there are still real unknowns here. What’s clear enough is the lesson: as long as a well-timed phone call can beat a multimillion-dollar security stack, the phones will keep ringing.

Meta Says Its AI Model Hacked Another Company, Adding to Worries About Bots Going Rogue

Previous article

OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation

Next article

You may also like

Comments

Comments are closed.

More in Finance