Dozens of U.S. financial firms targeted in vishing campaign

Dozens of U.S. financial firms targeted in vishing campaign

Google says the attackers used fake help-desk calls and spoofed login pages, then sought $750,000 to $3 million and in some cases threatened victims through public leak sites.

BTC

Fact Check
The primary Bloomberg article confirms the central claim: a wave of sophisticated cyberattacks targeted Wall Street firms including Two Sigma Investments, Citadel, Point72 Asset Management, and several private equity firms. This is echoed consistently across ChainCatcher, RootData, and BlockBeats, all of which trace back to the same Bloomberg report. The specific 'vishing'/social-engineering method is asserted by the BlockBeats retelling but was not explicitly verified in the Bloomberg summary retrieved; RootData notes attack methods remained unknown, creating minor uncertainty on that detail. The core event of major hedge funds being targeted is well-supported.
Summary

Major Wall Street private-equity and investment firms were swept into a vishing campaign that used phone impersonation and fake login pages to steal passwords and multifactor authentication codes, with Google describing the activity as part of a coordinated extortion effort. Reuters reported the targeted organizations included Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG, while Google's broader tracking identified threat groups including Redact, Pink, Falcon and Helix, which it said may operate under a larger cluster it calls UNC6671. Google said some of the groups run leak sites that threaten to publish stolen corporate data unless victims pay, with ransom demands typically ranging from $750,000 to $3 million. The researchers said a cryptocurrency wallet linked to one group received about $10 million in bitcoin in the first few months of this year, underscoring the scale of the operation. Google said the same actors have also targeted companies across manufacturing, real estate, healthcare, insurance, technology, transportation and hospitality, and that the focus on organizations involved in mergers, acquisitions, capital deployment and litigation suggests an effort to maximize extortion leverage by stealing highly sensitive information.

Terms & Concepts
  • vishing: A form of phishing that uses phone calls or voice messages to trick people into revealing sensitive information.
  • social-engineering: Techniques that manipulate people into giving up credentials or other confidential data.
  • multifactor authentication: A login safeguard that requires an extra verification step beyond a password.