A phone-first data-theft extortion campaign has targeted dozens of major US financial firms over the past month.
Ransom-seeking hackers have targeted dozens of major US financial institutions and other businesses in a campaign that relies heavily on phone-based social engineering, according to data from Google and internet intelligence platforms reviewed by Reuters.
The targets included private equity firms and financial companies such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s. Reuters also found evidence of attempted targeting involving hedge funds including Two Sigma Investments and Citadel.
Google said the attackers have operated under several extortion brands, including Redact, Pink, Falcon and Helix. Their exact relationships remain unclear, although Google threat analyst Austin Larsen said the groups appeared to share infrastructure.
Google did not identify the companies that were successfully compromised. Its research said some unnamed organizations had paid ransoms.
The attack started with a phone call
The campaign shows why sophisticated cybersecurity systems can still be undermined by basic social engineering.
Google said attackers called employees on their personal phones while posing as corporate help-desk staff. In some cases, the calls even displayed the legitimate help-desk number.
The attackers claimed there was an urgent request to update a passkey or multifactor authentication setting. Employees were then directed to fake login pages, with domains using names such as “passkeyhelpdesk” and “secure-passkey.”
Once victims entered their passwords, the hackers captured the authentication code sent by text message or generated by an authentication app, allowing them to take over the account while the call was still underway.
“Sophisticated is not the right word,” Larsen told Reuters. “It is just really effective.”
More than 200 companies targeted
The campaign was much broader than Wall Street. Reuters’ review of 72 malicious websites identified company-specific subdomains, while Google’s research and related data showed phishing infrastructure aimed at more than 200 organizations during a five-week period.
Other names in the data included Uber, Zillow, Levi Strauss and law firms Paul Hastings and Greenberg Traurig.
Greenberg Traurig said it “did not have a data breach given the layers of security protocols we have in place to protect client data and the firm.”
Why the human layer matters
The campaign is a reminder that cybersecurity spending does not eliminate the risk created by employees being manipulated. Companies can deploy strong authentication, endpoint protection and other technical controls, but attackers may simply target the person operating them.
For financial firms, the risk extends beyond stolen credentials. An account takeover could give criminals access to sensitive corporate information and potentially provide leverage for extortion.
The practical takeaway is that companies need to treat phone-based identity verification as seriously as phishing emails. Employees should be trained to independently verify unexpected IT requests rather than relying on caller ID, urgency or instructions supplied during a live call.
Also read: For another example of how attackers exploit trusted identities, read about the reported takeover of SpaceX and Starlink’s X accounts to promote a cryptocurrency scam.





