Ransomware Hackers Hit US Financial Firms with Low-Tech Attacks
By Business Desk
Major US financial firms and private equity companies targeted by ransomware hackers using ‘low-tech’ social engineering to steal employee credentials.
Over the past month, ransom-seeking hackers have unleashed a wave of “low-tech” social engineering attacks against prominent U.S. financial institutions and businesses. This sophisticated yet simple approach aimed to compromise major private equity firms and other key players by stealing employee credentials.
Targeted Firms Face Credential Theft
According to Google and internet intelligence data, these attackers, operating under aliases like Redact, Pink, Falcon, and Helix, established deceptive websites to pilfer employee passwords. The breadth of their targets underscores a calculated strategy to exploit organizations with highly sensitive data.
- Private Equity: Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG
- Financial Institutions: CME Group, Moody’s
- Hedge Funds: Point72 Asset Management, Two Sigma Investments, Citadel
- Other Companies: Uber, Zillow, Levi Strauss
- Law Firms: Paul Hastings, Greenberg Traurig
Social Engineering Tactics Revealed
The primary method involved hackers impersonating IT help desk personnel. They contacted employees directly on their personal cellphones, manipulating them into revealing critical access information.
- Tricking employees into divulging passkeys
- Coercing disclosure of multi-factor authentication codes
Google threat analyst Austin Larsen noted these groups strategically target industries based on potential financial incentives. They believe these organizations possess data valuable enough to compel a ransom payment.
Uncertainty on Breaches and Linkages
While some companies reportedly paid ransoms, the specific entities successfully compromised remain unclear. Greenberg Traurig, for instance, confirmed it was targeted but stated no data breach actually occurred.
Despite the use of various aliases, the hackers appear to be linked through shared infrastructure. This suggests a coordinated, persistent threat rather than disparate, isolated incidents, demanding a unified defense strategy from the financial sector.