
Google has warned that ransom-seeking hackers targeted dozens of US financial institutions and businesses, including Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG and Moody’s. The attackers reportedly called employees while posing as…
Google has warned that ransom-seeking hackers targeted dozens of US financial institutions and businesses, including Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG and Moody’s. The attackers reportedly called employees while posing as IT helpdesk staff, then directed them to fake login pages designed to steal passwords, multi-factor authentication tokens and cloud data.

Reuters’ analysis of 72 malicious websites linked to the campaign found traps tailored for more than 200 companies over five weeks, NDTV and The Times of India report. Google said the group operates under aliases including Redact, Pink, Falcon and Helix. Some companies reportedly paid ransoms, but Google did not identify them. Other targets included Uber, Zillow, Levi Strauss and several law firms.
The lazy narrative is that sophisticated financial firms were simply defeated by superior technology. The reported method was less dramatic but more practical: callers impersonated helpdesk staff and exploited employees using personal phones. Nor does being listed among targets prove that every company suffered a breach or paid. The useful test is whether firms can show how many accounts, tokens and records were accessed, and whether any ransom payments are confirmed.
Sources (3): ndtv.com, ndtv.com (2), timesofindia.indiatimes.com
This story was synthesised by AI from the 3 sources linked above.
Updated: this story now draws on 3 sources.