Ransom-seeking hackers employing social engineering tactics have targeted numerous prominent U.S. financial institutions and businesses over the past month, according to data reviewed from Google and internet intelligence platforms. The campaign has focused on private equity firms and other financial companies, seeking to steal employee credentials through phone calls and fraudulent websites.
The attackers created malicious websites designed to harvest passwords from employees at leading firms including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, and Moody’s. Additional targets reportedly included hedge funds such as Point72 Asset Management, Two Sigma Investments, and Citadel. Companies contacted for comment either declined or did not respond.
Google, which detailed the campaign in a blog post published on Thursday, identified the hackers operating under various names such as Redact, Pink, Falcon, and Helix. The company said some targeted organizations had reportedly paid ransoms, though it did not specify which ones. Google's analysis pointed to a shift in focus toward private equity, law firms, and financial ratings agencies.
According to Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, the attackers select industries based on financial incentives, aiming to access sensitive data that could prompt ransom payments. The hackers use meticulous social engineering, calling employees on personal phones while impersonating their internal IT help desks, often displaying legitimate company phone numbers to build trust.
During these calls, hackers claim there is an urgent IT directive requiring employees to update passkeys or multifactor authentication (MFA). Victims are directed to websites with domain names such as “passkeyhelpdesk” or “secure-passkey” where they enter their credentials. Concurrently, hackers capture authentication codes by maintaining phone contact, enabling them to hijack accounts immediately after the credential submission.
Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, emphasized that despite the availability of sophisticated cybersecurity tools and AI-driven defenses, these low-technology social engineering methods remain highly effective. “Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” Clark said.
While the hackers’ infrastructure appears linked across various groups, their exact identities and relationships remain unclear. Redact, formerly known as Darkfiles, stated on its darknet site that its members are neither politically nor morally motivated and declined to engage with the press.
This wave of attempted intrusions has generated concern across Wall Street. Point72 Asset Management confirmed it had been targeted, while other firms’ attempts were indicated by the review of 72 malicious websites tied to different companies. Google and internet security experts caution that although not all attempts succeeded, the prevalent use of social engineering highlights ongoing vulnerabilities in the financial sector’s human defenses.
