Google warns hackers are targeting finance firms through voice phishing: How the scam works
Google has warned that several hacking groups are targeting large financial and investment firms Through voice phishing.
The attackers call employees on their personal phones and pretend to be co-workers or IT support staff.
They then convince victims to enter their login details and multi-factor authentication codes on fake websites.
Hackers are successfully breaking into companies using simple tricks, even as AI-powered cyberattacks become more common. Google has warned that several hacking groups are targeting large financial and investment firms in the US through voice phishing, which is also known as vishing. Instead of using advanced hacking methods, the attackers call employees on their personal phones and pretend to be co-workers or IT support staff. They then convince victims to enter their login details and multi-factor authentication codes on fake websites. Once they gain access, the hackers steal sensitive company data and demand money by threatening to publish the stolen information if the victims refuse to pay.
SurveyAccording to Reuters, the companies targeted include major private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG. Google did not officially name the victims in its report.
Google has identified the hacking groups as Falcon, Helix, Pink and Redact. Google Researchers believe these groups may be linked to a larger operation tracked as UNC6671. But, it is still unclear if they are connected, work separately or share the same phishing tools.
“We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalise operations, hide overall breach volumes, and isolate any negotiation fallout,” the tech giant wrote in the report.
Also read: Google DeepMind CEO Demis Hassabis steps down: Here is what he will do now
Some of these hacking groups also run websites where they post details of their attacks. They use these sites to pressure victims into paying a ransom by threatening to leak stolen company data.
Google said the same hackers have also targeted companies in manufacturing, real estate, healthcare, insurance, technology, transportation and hospitality.
Also read: OpenAI says its AI agents hacked its own systems before breaching Hugging Face
More recently, the attackers have focused on legal and financial organisations. “Concentrating on organisations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximise leverage extortion demands,” wrote Google’s researchers.
Google also found that one cryptocurrency wallet linked to one of the hacking groups received around $10 million in bitcoin during the first few months of this year. “Initial ransom demands typically range from $1 million to upwards of $3 million,” the company said.
Ayushi works as Chief Copy Editor at Digit, covering everything from breaking tech news to in-depth smartphone reviews. Prior to Digit, she was part of the editorial team at IANS. View Full Profile
