Hackers targeted Blackstone, CME and other US firms, data shows
Key Points
- Hackers used low-tech phone calls pretending to be IT help desk staff, tricking employees into entering passwords on fake 'passkeyhelpdesk' websites while harvesting authentication codes live over the phone
- Google reported the hacking groups (operating as Redact, Pink, Falcon, and Helix) recently shifted focus to private equity firms, law firms, and financial ratings agencies based on financial calculations about which targets would pay ransoms
- Security experts note that despite sophisticated AI-driven security programs, basic social engineering tactics exploiting the 'human element' remain among the most effective hacking methods
AI Summary
Summary: Hackers Target Major U.S. Financial Firms with Phone-Based Social Engineering
Key Developments:
Ransom-seeking hackers created 72 malicious websites targeting employees at prominent U.S. financial institutions over the past month, according to Google and data reviewed by Reuters. Targeted firms include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, and Moody's.
Attack Method:
The hackers, operating under names including Redact, Pink, Falcon, and Helix, employed low-tech social engineering tactics. They called employees on personal cellphones, impersonating company IT help desks with spoofed phone numbers, claiming urgent password or multifactor authentication updates were needed. Victims were directed to fraudulent websites ("passkeyhelpdesk" or "secure-passkey") where hackers harvested credentials and authentication codes in real-time during calls.
Sector Shift:
Google confirmed the hackers recently pivoted focus to private equity firms, law firms, and financial ratings agencies, driven by financial calculations about which industries possess data valuable enough to pay ransoms. Google indicated some companies paid ransoms, though specific victims weren't identified.
Verification Status:
Reuters could not confirm which companies were successfully compromised. Google's principal threat analyst Austin Larsen noted all 72 malicious sites "were likely used in attempted intrusions" but "were not all successful."
Expert Assessment:
Cybersecurity experts emphasized that despite sophisticated security programs and AI-driven defenses, human vulnerability remains the weakest link. "That human element consistently is why this has exploded," said Lee Clark of Retail and Hospitality ISAC. Larsen described the tactic as "not sophisticated" but "really effective."
Most targeted companies declined comment or didn't respond to requests.
Model Analysis Breakdown
| Model | Sentiment | Confidence |
|---|---|---|
| GPT-5-mini | Bearish | 75% |
| Claude 4.5 Haiku | Bearish | 70% |
| Gemini 2.5 Flash | Neutral | 80% |
| Consensus | Bearish | 75% |