Overview
Over the past month, attackers seeking ransom payments have been observed targeting numerous U.S. financial institutions and related businesses by combining phone-based social engineering with custom-built credential-harvesting websites. Internet intelligence reviewed alongside published technical guidance from Google shows the campaign aimed at employees of private equity firms, market operators and ratings agencies, among other financial companies.
Targets named in technical data
The online traps identified in the data were crafted to mimic legitimate company resources and were tailored to employees at firms including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's, as well as a broader set of financial companies and other businesses. The analysis of domain and URL intelligence revealed malicious subdomains designed specifically for those organizations.
Who is behind the activity
Google, in a technical blog post about the campaign, said the attackers operate under a variety of names including Redact, Pink, Falcon and Helix. Google said the groups had shifted recent focus toward private equity firms, law firms and ratings agencies, selecting targets based on what the attackers assessed as likely financial value.
How the attacks worked
The attackers used meticulous social engineering, according to Google analysts. They called employees on personal cellphones while impersonating their company help desk. In some instances the call displayed the company help desk number. The caller would claim an urgent IT directive requiring employees to update passkeys or multifactor authentication settings and then direct them to a deceptive site with names such as "passkeyhelpdesk" or "secure-passkey."
If an employee entered their password and then provided a one-time code sent by text or generated by an authentication app, the attackers harvested those codes live over the phone and seized access to the account before the call ended.
Observations from threat analysts
Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, said the attackers were motivated by monetary calculations and targeted organizations they believed held sensitive data that would prompt payment to prevent exposure. "Really it's a money thing," Larsen said, adding that the groups tended to choose industries based on perceived financial return.
Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality ISAC, emphasized the role of the human element in the attacks. "Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," Clark said. He noted that human error continues to be a primary enabler of these compromises.
Scope and success unknown
Google said the malicious infrastructure listed in its report included dozens of sites and that the listed subdomains were likely used in attempted intrusions, while cautioning that they were not all successful. The public technical details did not identify which, if any, specific firms were successfully compromised. Google also noted that in some cases unnamed companies had paid ransoms to the attackers.
Responses from targeted firms
Several firms named in the intelligence review either declined to comment or did not immediately respond to requests for comment. KKR, Bain Capital, CME Group, TPG and Apollo declined to comment. Representatives for Blackstone, Bridgewater Associates and Moody's did not immediately reply to inquiries.
Industry implications
Experts say the campaign underscores that low-technology approaches - phone calls and social engineering - remain effective even against organizations with advanced security programs. The combination of convincing caller ID, urgent-sounding IT prompts and realistic-looking web pages allows attackers to bypass technical protections by exploiting routine human behavior.
Key points
- Attackers used phone calls plus customized credential-harvesting websites to target employees at major private equity firms, market operators and ratings agencies.
- Google identified the campaign and the group names Redact, Pink, Falcon and Helix; analysts said the attackers select targets based on financial motive.
- The schemes relied on live harvesting of passcodes and multifunction authentication codes, enabling account takeover even when multifactor controls were in place.
Risks and uncertainties
- It is unknown which specific companies, if any, were successfully compromised - the public technical data did not confirm successful intrusions.
- Some companies reportedly paid ransoms in certain cases, but the identities of those paying entities were not disclosed.
- The use of human-targeted social engineering means organizations with otherwise sophisticated defenses remain vulnerable, particularly across finance, legal, and ratings sectors.
Bottom line
The recent campaign shows that financially motivated attackers continue to blend simple, direct social engineering with carefully prepared online infrastructure to target high-value organizations in the financial sector. While investigators have cataloged the malicious domains and described the playbook, confirmation of successful compromises for specific firms has not been publicly established.