DistantNews
Support us
๐Ÿ‡ง๐Ÿ‡ฉ Bangladesh /Technology

Hackers target top US financial firms with fake calls, phishing sites

From Daily Star · () English

Translated from English, summarized and contextualized by DistantNews.

At a glance

News Named sources Context piece
  • Hackers are targeting prominent US financial institutions using sophisticated phishing campaigns involving fake help desk calls and websites.
  • Major firms like Blackstone, Bridgewater Associates, and Moody's are among the potential targets, with hackers aiming to steal employee credentials.
  • The attackers, operating under names like Redact and Pink, exploit low-tech tactics, demonstrating the continued effectiveness of social engineering in cybersecurity.

Cybercriminals are employing a sophisticated strategy involving fake help desk calls and phishing websites to compromise employee credentials at numerous high-profile U.S. financial institutions and businesses. Google and internet intelligence data reviewed by Reuters reveal that dozens of firms have been targeted over the past month.

The hackers have created websites specifically designed to steal passwords from employees of major private equity firms, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, and Moody's, as well as other financial companies. Google identified the hacking groups operating under various aliases such as Redact, Pink, Falcon, and Helix.

Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us

โ€” Lee ClarkAn industry expert explained the effectiveness of social engineering tactics used by hackers.

While Google confirmed that some companies paid ransoms, Reuters could not independently verify which firms were successfully compromised. Experts note that the hackers' use of seemingly low-tech tactics, like phone calls, highlights how traditional social engineering methods remain highly effective, even against organizations with advanced security measures. "Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," explained Lee Clark of the Retail and Hospitality ISAC, emphasizing the persistent vulnerability of the human element in cybersecurity.

Google's Threat Intelligence Group noted that the hackers target industries based on perceived financial gain, believing these firms possess data valuable enough to warrant ransom payments. The attackers focus on organizations where stolen data could lead to significant financial repercussions if leaked or compromised. The use of tailored subdomains for each targeted firm demonstrates a high level of planning and execution in these phishing campaigns.

Really itโ€™s a money thing. They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.

โ€” Austin LarsenA threat analyst at Google described the hackers' motivation.
DistantNews Editorial

Originally published by Daily Star in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.