
Hackers have targeted more than 200 prominent U.S. companies over the past month in a coordinated campaign aimed heavily at Wall Street, using fake corporate login pages and phone calls impersonating internal IT staff to steal employee credentials and multifactor-authentication codes.
The targets included Blackstone, Apollo Global Management, KKR, Bain Capital, TPG, Bridgewater Associates, CME Group and Moody’s, according to Google threat intelligence and internet data reviewed by Reuters. Hedge funds including Point72, Two Sigma and Citadel were also targeted, along with companies outside finance such as Uber, Zillow and Levi Strauss.
The attack method was strikingly simple. Hackers created websites designed to look like legitimate company portals, then called employees while pretending to be technical-support staff. Victims were directed to the fake sites and asked to enter passwords and temporary authentication codes, allowing attackers to bypass security systems that normally require more than a password.
The campaign shows why the most expensive cybersecurity infrastructure can still fail when attackers convince employees to voluntarily surrender the credentials protecting it.
Google said the hackers appeared primarily motivated by money and had demanded ransoms from some victims. It did not identify which companies were successfully breached, though it confirmed that some organizations caught in the broader campaign paid attackers. The groups have operated under several aliases, including Redact, Pink, Falcon and Helix, and their precise identities remain unclear.
Financial firms are particularly attractive because a compromised employee account can provide access not only to internal communications but to investment information, client records, transaction data and proprietary systems. For private-equity and hedge-fund firms, even information that never results in a direct cash theft can carry enormous value if it exposes transactions, portfolio strategy or trading activity.
The campaign also complicates a security practice many companies have treated as sufficient: multifactor authentication. Temporary codes are effective against stolen passwords, but they offer far less protection when an employee is tricked into giving both the password and authentication code directly to the attacker.
For businesses, the operational response increasingly requires procedures outside the software itself. Employees need a separate way to verify whether someone claiming to be from internal IT actually initiated a call, while privileged accounts may require authentication methods that cannot be relayed over the phone.
The broader lesson is that cybercrime is shifting toward the employee rather than simply attacking the machine. As companies spend more on firewalls, monitoring systems and identity controls, criminals are increasingly targeting the person authorized to get through them.
JBizNews Desk | New York
© JBizNews.com All Rights Reserved.
Reproduction or distribution without written permission is prohibited.