WASHINGTON: Cybercriminals using phone-based social engineering techniques have targeted dozens of major US financial institutions and other businesses in recent weeks, according to Google and internet intelligence data reviewed by Reuters.
The campaign has reportedly focused on employees of private equity firms, financial companies and other organisations, with attackers creating fraudulent websites designed to obtain employees’ login credentials.
Among the companies identified in the data were Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s, along with a number of other businesses.
Google said the hacking operation involves groups using several names, including Redact, Pink, Falcon and Helix. The technology company said some targeted organisations had paid ransoms, although it did not identify them. Reuters was unable to determine how many of the targeted companies were successfully compromised.
Cybersecurity experts said the campaign highlights how traditional social engineering methods remain effective despite the growing use of advanced security systems and artificial intelligence in cyber defence.
According to Google, the attackers have increasingly focused on sectors where sensitive financial information is held, including private equity companies, law firms and financial ratings agencies.
The attackers reportedly contacted employees on their personal phones while posing as members of their company’s IT or help-desk teams. In some cases, the calls appeared to originate from legitimate company phone numbers, making the deception more convincing.
The targets were reportedly told that an urgent security update was required and were directed to fraudulent websites. The websites were designed to resemble legitimate company or security services and were used to obtain sensitive login information.
Google threat analyst Austin Larsen said the approach was not particularly technically sophisticated but had proved effective because it exploited human behaviour and trust.
Data reviewed by Reuters indicated that the hackers had created targeted online infrastructure for more than 200 companies over a period of about five weeks. The targets included businesses from several sectors, including ride-hailing, online brokerage, retail and legal services.
Among the companies appearing in the data were Uber, Zillow and Levi Strauss, as well as law firms Paul Hastings and Greenberg Traurig.
Greenberg Traurig said it had not suffered a data breach, citing its security measures designed to protect client information.
The campaign has also attracted attention on Wall Street. Point72 Asset Management reportedly informed investors that it had been targeted, while sources said other investment firms, including Two Sigma Investments and Citadel, had also faced attempted intrusions.
Google said the different groups using various aliases appeared to share some technical infrastructure, although their exact relationships and identities remain unclear.
Cybersecurity researchers say the campaign demonstrates that even well-protected organisations remain vulnerable when attackers succeed in manipulating employees rather than directly defeating technological security systems.
Authorities and security experts continue to urge companies to strengthen employee awareness and verification procedures as criminals increasingly combine conventional phone scams with online attacks.
