Hackers Target Blackstone, CME, KKR, Other Top Private Equity Firms In Ransom Campaign

Hackers targeting US financial firms are using fake IT calls and fraudulent websites to steal employee passwords and authentication codes.

Advertisement
Read Time: 2 mins
Companies including Blackstone, CME Group, Apollo, KKR, Bain Capital and TPG have been targeted in the campaign.
AI Generated Image

Hackers seeking ransom payments have stepped up attacks on major US financial and professional services companies, using fraudulent phone calls and websites to obtain employee credentials, according to Google and internet intelligence data reviewed by Reuters.

The campaign has targeted prominent private equity firms and financial companies, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's, highlighting the vulnerability of organisations that hold valuable financial and corporate information.

Google said the attackers have operated under several names, including Redact, Pink, Falcon and Helix, and have recently expanded their focus to private equity firms, law practices and credit-rating agencies.

Some unnamed organisations paid ransoms, although it was not clear which companies were successfully breached, according to Google. Reuters identified company-specific websites linked to the campaign by examining 72 malicious web addresses cited by Google's threat intelligence team. Internet intelligence services identified subdomains created to resemble the targeted organisations.

ALSO READ: Meta AI Model Accessed Internet, Hacked Outside Firm

The attackers' approach relied heavily on social engineering. Google said they contacted employees through personal phones while posing as internal IT or help-desk personnel. The callers would claim that an urgent security update was required and direct employees to fake websites designed to capture passwords and authentication information.

The attackers could then obtain one-time verification codes, including those generated by authentication applications or delivered through text messages, allowing them to seize control of accounts during the call.

Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, told Reuters that the attackers select organisations where stolen information could potentially generate substantial ransom payments.

Also Read: Rogue OpenAI Agent Spent Days Hacking Hugging Face, Went Unnoticed For A Week

Essential Business Intelligence, Sharp Market Insights, Practical Personal Finance Advice, Daily Fuel, Gold and Silver Prices and Latest Stories — On NDTV Profit.


Loading...