Exclusive: Phone-Wielding Ransom Hackers Set Sights on Top U.S. Financial Firms, Data Shows

By Emily Carter|Business & Economy Reporter
Exclusive: Phone-Wielding Ransom Hackers Set Sights on Top U.S. Financial Firms, Data Shows

By Raphael Satter, AJ Vicens and Anirban Sen

WASHINGTON, Aug 6 (Reuters) - Over the past month, ransomware hackers have trained their sights on dozens of prominent U.S. financial institutions and other businesses, using a surprisingly low-tech method: phone calls. The campaign, which has rattled Wall Street, was detailed in Google threat intelligence and internet data reviewed by Reuters.

The hackers built fake websites designed to steal employee credentials from a roster of blue-chip firms, including private equity giants Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's, along with other businesses, the data shows.

Google revealed the hacking campaign in a blog post on Thursday, saying the attackers operate under various aliases such as Redact, Pink, Falcon and Helix. The company declined to comment on Reuters' findings, but its blog noted that in some unnamed cases, companies paid ransoms. Reuters could not determine which firms, if any, were successfully breached.

Security experts say the campaign underscores an uncomfortable truth for the financial industry: even as defenses become more sophisticated and AI-powered threats proliferate, the oldest tricks still work. The hackers' reliance on phone calls and social engineering shows that human vulnerability remains the weakest link, they say.

"Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," said Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality ISAC, an industry information-sharing and analysis group. "That human element consistently is why this has exploded in the way it has."

KKR, Bain Capital, Clearlake Capital, CME, TPG and Apollo declined to comment. Blackstone, Bridgewater Associates and Moody's did not immediately respond to requests for comment.

HACKERS SHIFT ATTENTION: GOOGLE

In its blog post, Google, a unit of Alphabet, said the hackers had recently pivoted to private equity, law firms and financial ratings agencies. Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, said the attackers typically choose targets based on financial calculations, and they often succeed.

"Really, it's a money thing," Larsen said. "They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it."

Google did not name any targets. Reuters reverse-engineered many of the company-specific online traps by running the 72 malicious websites Google listed through web intelligence platforms such as DomainTools and urlscan, which flagged malicious subdomains tailored to each firm.

Speaking generally about the subdomains, Larsen said, "They all were likely used in attempted intrusions," though he cautioned, "They were not all successful."

Google described the hackers' methods as "meticulous social engineering tactics." Attackers called employees on their personal cellphones, pretending to be from corporate IT help desks, sometimes even spoofing the correct help desk number. They would tell targets there was an urgent directive to update passkeys or multifactor authentication, then steer them to booby-trapped websites with names like "passkeyhelpdesk" or "secure-passkey."

If the employee entered their password, the hackers harvested the fail-safe passcode — typically sent by text or generated by an app — live over the phone, hijacking the account before the call ended.

Larsen cautioned against calling the tactic sophisticated. "Sophisticated is not the right word," he said. "It is just really effective."

SHIFTING ALIASES

Reuters could not reach the alleged hackers. Redact — previously known as Blackfile — said on its darknet site that its hackers "are not politically or morally motivated" and were "not currently taking questions from the press." On its own site, Falcon acknowledged affiliation with Redact but said it had nothing to do with Helix or Pink.

Larsen said it remained unclear who the hackers are or how they relate to one another. Though they operate under different names, he said they appear to be linked by common infrastructure. "There are still some unknowns here," he said.

The hacking attempts, a few of which were earlier reported by Bloomberg, have caused a stir on Wall Street. Point72 Asset Management told investors on Wednesday that it had been targeted, according to a source familiar with the matter. That source and a second person said the hackers also attempted to breach other hedge funds, including Two Sigma Investments and Citadel, whose names appeared in the data reviewed by Reuters.

Two Sigma has not returned messages seeking comment. Citadel and Point72 declined to comment.

Before focusing on financial institutions, the same hackers built digital traps for more than 200 companies in the past five weeks, according to Google's blog post and the data. Targets included ride-hailing company Uber, online broker Zillow, jeans brand Levi Strauss, and law firms Paul Hastings and Greenberg Traurig.

Uber, Zillow, Paul Hastings and Levi Strauss did not return messages seeking comment. In a statement, Greenberg Traurig said it "did not have a data breach given the layers of security protocols we have in place to protect client data and the firm." It did not elaborate.

(Reporting by Raphael Satter, AJ Vicens and Anirban Sen; Editing by Rod Nickel and Nick Zieminski)

Share

This Post Has 0 Comments

No comments yet. Be the first to comment!

Leave a Reply