Google reports that cybercriminals are contacting employees of financial companies to breach systems and extort their targets.

Google reports that cybercriminals are contacting employees of financial companies to breach systems and extort their targets.

In the era of AI-driven autonomous cyber assaults, the basic, established hacking methods of deceiving victims into actions they ought to avoid continue to yield significant outcomes. 

Unidentified hacking groups are infiltrating major financial and investment companies in the United States with the intent of stealing confidential information to extort the victims by threatening to release it, as reported by Google’s security researchers on Thursday.

The firm did not disclose the identities of the victims, but Reuters mentioned among them prominent private equity firms including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. 

The hacking collectives, which Google identified as Falcon, Helix, Pink, and Redact, are employing a traditional method to breach these firms: making phone calls to employees’ personal cellphones where the hackers impersonate colleagues or IT support personnel, attempting to deceive targets into providing their credentials and multi-factor codes on fake websites, according to Google. This tactic is known in cybersecurity as voice phishing, or vishing.

Some groups highlighted by Google operate websites where they advertise their hacks and threaten to disclose the stolen data to extort the victims into paying a ransom, a prevalent tactic among cybercriminals.

Image Credits:Google /

“We engage in every negotiation on professional terms. The release of your data is never our desired outcome; it is a result of declining to cooperate, intentional delays, or failing to adhere to an agreement,” stated one of the websites. “Act swiftly and in good faith, and the issue is settled without further complications.”

Researchers at Google indicated that the various groups might all belong to a broader collective that the company monitors under the designation UNC6671. However, it remains unclear if they are partners, splinter factions, or if they share the same Phishing-as-a-Service framework. 

“We suspect this likely indicates a coordinated assembly of threat actors managing multiple public extortion brands perhaps to compartmentalize operations, obscure overall breach figures, and mitigate any fallout from negotiations,” the report articulated.

Contact Us

Do you possess more information regarding these data breaches? We’d like to hear from you. Using a non-work device and network, you can securely reach out to Lorenzo Franceschi-Bicchierai on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or through email.

As per Google, the hacking groups have previously targeted significant firms across the manufacturing, real estate, healthcare, and insurance industries, as well as in technology, transportation, and hospitality sectors with the aim of stealing “valuable intellectual property, software source code, or sensitive VIP client information.”

More recently, these hackers have focused on legal and financial institutions, including private equity firms. “Targeting organizations involved in mergers, acquisitions, capital distribution, and litigation may indicate a strategy aimed at extracting high-value corporate and confidential data to enhance extortion leverage,” stated Google’s researchers. 

Google reported that one cryptocurrency wallet linked to one of the hacking groups received approximately $10 million in bitcoin during the first few months of this year, and that the hackers typically demand between $750,000 and $3 million from their victims.

Laurie Bischel, a representative for CME Group, chose not to comment.

Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s, and TPG did not respond to requests for comments.

When you make purchases through links in our articles, we may earn a small commission. This does not influence our editorial independence.

Leave a Reply