🏠 News Empire
india

Hackers Use Phone Calls to Target Blackstone, KKR and Other Financial Firms

Published on: 06 Aug 2026, 06:04 PM
Hackers Use Phone Calls to Target Blackstone, KKR and Other Financial Firms

The financial sector has long been a prime target for cybercriminals. Over the past month, that trend has continued with a sophisticated yet surprisingly low-tech campaign that aimed to breach some of the biggest names in finance. According to data from Google and internet intelligence platforms reviewed by Reuters, ransom-seeking hackers used phone calls to trick employees into giving up their login credentials.

The hackers created malicious websites to steal passwords from employees of private equity firms and companies including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's, as well as other financial and business organisations. The list highlights the wide net cast by the attackers.

Google, in a blog post on Thursday, said the hackers operated under names such as Redact, Pink, Falcon and Helix. The company declined to comment on Reuters' findings but said that in some cases, companies it did not name had paid ransoms to the hackers. Reuters could not establish which companies were successfully compromised.

Security experts say the hackers' use of low-tech tactics, such as direct phone calls, illustrates that even the most advanced security programmes are vulnerable to human error. If successful, the attacks could have compromised data from some of the largest US private equity firms, which manage investments and provide capital to companies across various industries.

"Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," said Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality Information Sharing and Analysis Center (ISAC). "That human element consistently is why this has exploded in the way it has."

Several companies named in the report, including KKR, Bain Capital, CME, TPG and Apollo, declined to comment. Blackstone, Bridgewater Associates and Moody's did not immediately respond to requests for comment.

In its blog post, Google — a unit of Alphabet — said the hackers had recently turned their attention to private equity, law firms and financial ratings agencies. Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, said the hackers generally targeted industries based on financial calculations, often succeeding.

"Really it's a money thing," Larsen said. "They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it."

Google did not identify the targeted companies by name. However, Reuters was able to reverse-engineer many of the company-specific online traps by running the 72 malicious websites listed in Google's report through web intelligence platforms such as DomainTools and urlscan. These platforms flagged malicious subdomains tailored to each firm.

Speaking generally about the subdomains, Larsen said "they all were likely used in attempted intrusions," but cautioned "they were not all successful."

Google said the hackers used "meticulous social engineering tactics," reaching employees on their personal cell phones while pretending to call from the company's help desk, sometimes displaying the correct help desk number. The hackers told employees there was an urgent directive from IT to update their passkeys or multifactor authentication, then steered them to fraudulent websites named "passkeyhelpdesk" or "secure-passkey."

If an employee followed the instructions and entered their password, the hackers could harvest the fail-safe passcode — typically sent by text or generated by an app — live over the phone, and hijack the account before the call ended.

Larsen said the tactic should not be considered advanced. "Sophisticated is not the right word," he said. "It is just really effective."

The episode underscores a broader reality in cybersecurity: attackers are increasingly exploiting human psychology rather than relying solely on technical exploits. For financial institutions, the response involves not just stronger technology but also continuous employee education and alertness against such social engineering approaches.

Latest in India 10
Bangladesh sets August 20 for presidential election
india

Bangladesh sets August 20 for presidential election

Bangladesh's Election Commission announced that the presidential election will be held on August 20. This follows President Mohammed Shahabuddin's resignation on health grounds, with the ruling BNP yet to name a candidate for the largely ceremonial post.

The Hindu 06 Aug 2026, 06:20 PM
Read More →
→ View All India News