Hackers Target Blackstone, CME and Other Wall Street Firms in Phone-Based Scam

Hackers targeted major financial firms with help-desk vishing and real-time MFA interception. Here’s how the campaign worked and how to respond.

Aug 7, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A phone-first data-theft extortion campaign has targeted dozens of major US financial firms over the past month.

Ransom-seeking hackers have targeted dozens of major US financial institutions and other businesses in a campaign that relies heavily on phone-based social engineering, according to data from Google and internet intelligence platforms reviewed by Reuters.

The targets included private equity firms and financial companies such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s. Reuters also found evidence of attempted targeting involving hedge funds including Two Sigma Investments and Citadel.

Google said the attackers have operated under several extortion brands, including Redact, Pink, Falcon and Helix. Their exact relationships remain unclear, although Google threat analyst Austin Larsen said the groups appeared to share infrastructure.

Google did not identify the companies that were successfully compromised. Its research said some unnamed organizations had paid ransoms.

The attack started with a phone call

The campaign shows why sophisticated cybersecurity systems can still be undermined by basic social engineering.

Google said attackers called employees on their personal phones while posing as corporate help-desk staff. In some cases, the calls even displayed the legitimate help-desk number.

The attackers claimed there was an urgent request to update a passkey or multifactor authentication setting. Employees were then directed to fake login pages, with domains using names such as “passkeyhelpdesk” and “secure-passkey.”

Once victims entered their passwords, the hackers captured the authentication code sent by text message or generated by an authentication app, allowing them to take over the account while the call was still underway.

“Sophisticated is not the right word,” Larsen told Reuters. “It is just really effective.”

More than 200 companies targeted

Advertisement

The campaign was much broader than Wall Street. Reuters’ review of 72 malicious websites identified company-specific subdomains, while Google’s research and related data showed phishing infrastructure aimed at more than 200 organizations during a five-week period.

Other names in the data included Uber, Zillow, Levi Strauss and law firms Paul Hastings and Greenberg Traurig.

Greenberg Traurig said it “did not have a data breach given the layers of security protocols we have in place to protect client data and the firm.”

Why the human layer matters

The campaign is a reminder that cybersecurity spending does not eliminate the risk created by employees being manipulated. Companies can deploy strong authentication, endpoint protection and other technical controls, but attackers may simply target the person operating them.

For financial firms, the risk extends beyond stolen credentials. An account takeover could give criminals access to sensitive corporate information and potentially provide leverage for extortion.

The practical takeaway is that companies need to treat phone-based identity verification as seriously as phishing emails. Employees should be trained to independently verify unexpected IT requests rather than relying on caller ID, urgency or instructions supplied during a live call.

Also read: For another example of how attackers exploit trusted identities, read about the reported takeover of SpaceX and Starlink’s X accounts to promote a cryptocurrency scam.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.