Google Warns of Vishing Attacks Targeting US Financial Firms

Google Warns US Financial Firms About Rising Vishing Attacks as Cybercriminals Target Sensitive Data Through Fake Calls and Phishing Websites.
Google Warns of Vishing Attacks Targeting US Financial Firms
Written By:
Akshita Pidiha
Reviewed By:
Aishwarya Avsk
Published on

Cybercriminals are targeting major financial and investment firms in the US through voice phishing campaigns. The cybercriminals are trying to steal sensitive corporate data and using it for extortion, according to a new report from Google's security researchers.

The researchers said the attackers rely on phone calls to employees instead of advanced technical exploits. During these calls, they pose as colleagues or IT support staff and persuade employees to enter their login credentials and multi-factor authentication codes on fake websites. This method, known as voice phishing or vishing, has emerged as the main entry point in the latest campaign.

Multiple Groups Linked 

Google did not identify the affected organizations in its report. According to Reuters, targets include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's and TPG. The attackers are seeking access to confidential corporate information that can later be used to pressure companies into paying ransom demands. Once data is stolen, some of the groups publish threats on dedicated leak websites and warn that sensitive information will be released if negotiations fail.

Google has identified four hacking groups involved in the activity and tracks them under the names Falcon, Helix, Pink and Redact. The company believes these groups may operate under a broader threat cluster known as UNC6671. 

Researchers said it is still unclear whether the groups work as affiliates, operate independently or share the same phishing infrastructure. Google said the structure appears organized, with separate public identities helping the attackers isolate operations and manage extortion efforts.

High-Value Corporate Data

The report said the same threat actors have previously targeted companies in manufacturing, healthcare, insurance, transportation, hospitality, technology and real estate. 

Their recent focus has shifted to financial firms and legal organizations that handle mergers, acquisitions, investments and litigation. Google said such organizations hold valuable corporate information that can increase pressure during ransom negotiations.

The findings also show that traditional social engineering tactics continue to deliver results even as cyber threats evolve. While artificial intelligence is reshaping parts of the cyber landscape, attackers are still succeeding through direct human manipulation. 

Google's researchers stated that the latest campaign shows that convincing employees to surrender credentials through trusted conversations continues to be one of the most effective methods for gaining access to corporate networks.

Also Read: White House to Meet OpenAI, Meta, Google Over AI Cybersecurity Tests

Analytics Insight UAE: Top Tech News Website in UAE, Dubai & Middle East
www.analyticsinsight.ae