Blackstone, KKR and other finance giants targeted in password theft hacking campaign

U.S. financial firms and businesses faced phone-based hacking attacks recently. Hackers used fake websites to steal employee passwords and gain access. These attacks targeted private equity, law firms, and financial ratings agencies. Sophisticated...

Reuters
The breaches highlight that many organizations remain highly vulnerable to human-targeted cyber threats despite existing security measures.
Dozens of U.S. financial institutions and other businesses over the past month have been targeted by ransom-seeking hackers who use phone calls to compromise their victims, according to Google and internet intelligence data reviewed by Reuters.

According to the data, hackers utilised websites to steal passwords from employees of private equity firms such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's, as well as a host of financial companies and other businesses.

Google, in a blog post on the hacking campaign published on Thursday, said that the hackers operated under a range of aliases, including Redact, Pink, Falcon and Helix.


According to Reuters, the internet company declined to comment on its findings but revealed that some companies not named by Google had paid ransoms to the attackers. It was unable to verify which companies were successfully breached.

Experts noted the use of low-tech methods like phone calls to target major companies, highlighting that even organisations with advanced security systems remain exposed to cyber threats. Successful attacks could potentially put sensitive data belonging to leading U.S. private equity firms and the companies at risk.

“Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” said Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, an industry information-sharing and analysis group, to Reuters.
ADVERTISEMENT

“That human element consistently is why this has exploded in the way it has," he added.

New targets

In Google’s blog post, the hackers were found to have recently turned their attention towards private equity firms, law firms and financial ratings agencies.

Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, told Reuters that hackers typically chose their targets by weighing potential financial gains, a strategy that has often proven effective.
ADVERTISEMENT

“Really it’s a money thing,” Larsen said. “They think that these firms or organisations have data sensitive enough that, if taken, they would pay to prevent it,” he added.

The internet company did not identify any of the hackers’ targets by name.
ADVERTISEMENT

Several company-specific online traps used by the hackers, created by running the 72 malicious websites listed by Google in its report through web intelligence platforms such as DomainTools and urlscan, which flagged malicious subdomains tailored to each firm, were reverse engineered by Reuters.

When speaking in general about the subdomains, Larsen said, “They all were likely used in attempted intrusions.”

However, “they were not all successful,” he cautioned.

Google reported to Reuters that the hackers employed sophisticated social engineering methods, contacting employees on their personal phones while posing as company IT help desk representatives, sometimes even spoofing legitimate help desk numbers. They falsely claimed that urgent security updates were required and directed victims to fake websites such as “passkeyhelpdesk” or “secure-passkey.” When employees entered their credentials, the attackers captured authentication codes in real time and took control of their accounts before ending the call.

According to Reuters, Larsen said it was wrong to think of the tactic as particularly advanced.

“Sophisticated is not the right word,” he said. “It is just really effective,” he added.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › News › International › World News › Blackstone, KKR and other finance giants targeted in password theft hacking campaign
Text Size:AAA
Success
This article has been saved

*

+