Ransom-seeking hackers who use phone calls to compromise their victims targeted dozens of prominent U.S. financial institutions and other businesses over the past month, according to Google and internet intelligence data reviewed by Reuters.
The data shows the hackers devised websites aimed at stealing passwords from employees of private equity firms and companies including Blackstone BX.N, Bridgewater Associates, Apollo Global Management APO.N, Bain Capital, KKR KKR.N, TPG TPG.O, CME Group CME.O and Moody's MCO.N, as well as a host of financial companies and other businesses. Internet company Google said in a blog post about the hacking campaign published on Thursday that the hackers operate under a range of names, including Redact, Pink, Falcon, and Helix.
Google declined to comment on Reuters findings. Its blog said in some cases companies, which it did not name, paid ransoms to the hackers. Reuters could not establish which companies the hackers successfully compromised.
Experts say the hackers' use of low-tech tactics such as phone calls to target the financial industry illustrates how, despite sophisticated security programs and AI-driven threats, the oldest tactics still rank among the most effective. If successful, the hacks could compromise data of some of the biggest U.S. private equity firms that provide capital to companies.
“Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” said Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, an industry information sharing and analysis group.
“That human element consistently is why this has exploded in the way it has," he said.
KKR, Bain Capital, CME, TPG and Apollo declined to comment. Blackstone, Bridgewater Associates and Moody's did not immediately respond to requests for comment.