Major US financial firms targeted in extensive phone-phishing campaign

Warda Fatima
By
Warda Fatima
Warda Fatima is a BS English literature student at Government College University, Lahore.
2 Min Read

Summary

  • A technical report from Google’s Threat Intelligence Group revealed that hackers created 72 malicious websites designed to steal corporate login credentials.
  • According to threat intelligence analysis, the campaign represents a strategic pivot toward private equity firms, law practices, and financial rating agencies, driven by the assessment that these targets hold sensitive commercial data worth paying substantial ransoms to protect.
  • While digital intelligence data identified fake portals created for over 200 organisations, including Uber, Levi Strauss, and several major law firms, it remains unconfirmed which specific financial targets experienced compromised systems.
AI Generated Summary

Ransom-seeking cybercriminals have launched a coordinated campaign targeting high-profile US financial institutions, including Blackstone, Apollo Global Management, KKR, Bain Capital, and CME Group.

A technical report from Google’s Threat Intelligence Group revealed that hackers created 72 malicious websites designed to steal corporate login credentials. Operatives used social engineering tactics, reaching employees directly on personal mobile phones while spoofing corporate IT helpdesk numbers.

Under the guise of urgent system updates, callers guided staff to fraudulent domains such as “passkeyhelpdesk” or “secure-passkey” to capture login credentials and multi-factor authentication passcodes in real time.

According to threat intelligence analysis, the campaign represents a strategic pivot toward private equity firms, law practices, and financial rating agencies, driven by the assessment that these targets hold sensitive commercial data worth paying substantial ransoms to protect.

While digital intelligence data identified fake portals created for over 200 organisations, including Uber, Levi Strauss, and several major law firms, it remains unconfirmed which specific financial targets experienced compromised systems.

The threat actors operating under names such as Redact, Falcon, Helix, and Pink share common digital infrastructure.

Analysts noted that despite advanced enterprise perimeter security, direct voice-phishing techniques exploiting human trust continue to rank among the most effective cyber-intrusion vectors.

We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com
Share This Article
Warda Fatima is a BS English literature student at Government College University, Lahore.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *