Ransomware Hackers Hit US Financial Firms with Low-Tech Attacks

By Business DeskRansomware Hackers Hit US Financial Firms with Low-Tech Attacks

Major US financial firms and private equity companies targeted by ransomware hackers using ‘low-tech’ social engineering to steal employee credentials.

Over the past month, ransom-seeking hackers have unleashed a wave of “low-tech” social engineering attacks against prominent U.S. financial institutions and businesses. This sophisticated yet simple approach aimed to compromise major private equity firms and other key players by stealing employee credentials.

Targeted Firms Face Credential Theft

According to Google and internet intelligence data, these attackers, operating under aliases like Redact, Pink, Falcon, and Helix, established deceptive websites to pilfer employee passwords. The breadth of their targets underscores a calculated strategy to exploit organizations with highly sensitive data.

  • Private Equity: Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG
  • Financial Institutions: CME Group, Moody’s
  • Hedge Funds: Point72 Asset Management, Two Sigma Investments, Citadel
  • Other Companies: Uber, Zillow, Levi Strauss
  • Law Firms: Paul Hastings, Greenberg Traurig

Social Engineering Tactics Revealed

The primary method involved hackers impersonating IT help desk personnel. They contacted employees directly on their personal cellphones, manipulating them into revealing critical access information.

  • Tricking employees into divulging passkeys
  • Coercing disclosure of multi-factor authentication codes

Google threat analyst Austin Larsen noted these groups strategically target industries based on potential financial incentives. They believe these organizations possess data valuable enough to compel a ransom payment.

Uncertainty on Breaches and Linkages

While some companies reportedly paid ransoms, the specific entities successfully compromised remain unclear. Greenberg Traurig, for instance, confirmed it was targeted but stated no data breach actually occurred.

Despite the use of various aliases, the hackers appear to be linked through shared infrastructure. This suggests a coordinated, persistent threat rather than disparate, isolated incidents, demanding a unified defense strategy from the financial sector.

Home/business/Article