Ransom-seeking cybercriminals have launched a massive social engineering campaign targeting dozens of leading U.S. financial institutions, private equity firms, and major corporations, using voice phishing (vishing) to bypass MFA defenses.
📊 Key Scale, Targets & Attack Infrastructure
- High-Profile Financial Targets: Cybercriminals created digital traps targeting leaders including Blackstone, KKR, Bain Capital, Apollo Global Management, TPG, Clearlake Capital, Bridgewater Associates, Point72, Citadel, Two Sigma, CME Group, and Moody’s.
- Broader Corporate Reach: Traps targeted over 200 companies in 5 weeks, spanning law firms (Paul Hastings, Greenberg Traurig) and commercial brands (Uber, Zillow, Levi Strauss).
- Malicious Infrastructure: Google Threat Intelligence identified 72 malicious websites and custom subdomains (e.g., passkeyhelpdesk, secure-passkey) designed to capture employee login credentials.
- Threat Groups: Operating under overlapping darknet aliases including Redact (formerly Blackfile), Pink, Falcon, and Helix, linked by shared network infrastructure.
💡 Social Engineering Tactics & Risks
- Vishing Mechanics: Attackers called employees on personal cellphones spoofing official IT help desk numbers, claiming an urgent IT directive to update passkeys, and stealing live MFA codes over the phone to hijack accounts.
- Ransom Motivations: Google reported that some targeted firms paid ransoms to prevent leaks of highly sensitive M&A and financial data.
💡 The Strategic Takeaway
This widespread campaign underscores that human engineering remains the most effective weapon against high-tech perimeter security. Financial institutions must implement strict out-of-band identity verification protocols to protect sensitive deal flow and client data from social engineering.
