Stock Markets August 6, 2026 01:03 PM

Phone-based ransomware campaign targeted U.S. financial firms, including major private equity and market players

Hackers used social engineering and crafted web pages to capture employee credentials at multiple institutions, Google intelligence shows

By Maya Rios
Share
Twitter Reddit Facebook LinkedIn
MCO CME BX APO KKR

Security researchers and internet intelligence data indicate a recent surge in ransom-seeking attackers who employ phone calls and tailored websites to steal employee passkeys and multifactor codes from dozens of prominent U.S. financial firms. The campaign focused on private equity firms, market operators and ratings agencies, using social engineering to trick staff into entering credentials on fraudulent pages while relaying codes live over the phone.

Phone-based ransomware campaign targeted U.S. financial firms, including major private equity and market players
MCO CME BX APO KKR
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Attackers combined phone-based social engineering with customized credential-stealing websites to target employees at private equity firms, market operators and ratings agencies.
  • Google identified groups using the names Redact, Pink, Falcon and Helix and said targets were chosen for perceived financial value.
  • The campaign harvested passwords and live multifactor codes, enabling account takeover despite multifactor authentication protections.

Overview

Over the past month, attackers seeking ransom payments have been observed targeting numerous U.S. financial institutions and related businesses by combining phone-based social engineering with custom-built credential-harvesting websites. Internet intelligence reviewed alongside published technical guidance from Google shows the campaign aimed at employees of private equity firms, market operators and ratings agencies, among other financial companies.

Targets named in technical data

The online traps identified in the data were crafted to mimic legitimate company resources and were tailored to employees at firms including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody's, as well as a broader set of financial companies and other businesses. The analysis of domain and URL intelligence revealed malicious subdomains designed specifically for those organizations.

Who is behind the activity

Google, in a technical blog post about the campaign, said the attackers operate under a variety of names including Redact, Pink, Falcon and Helix. Google said the groups had shifted recent focus toward private equity firms, law firms and ratings agencies, selecting targets based on what the attackers assessed as likely financial value.

How the attacks worked

The attackers used meticulous social engineering, according to Google analysts. They called employees on personal cellphones while impersonating their company help desk. In some instances the call displayed the company help desk number. The caller would claim an urgent IT directive requiring employees to update passkeys or multifactor authentication settings and then direct them to a deceptive site with names such as "passkeyhelpdesk" or "secure-passkey."

If an employee entered their password and then provided a one-time code sent by text or generated by an authentication app, the attackers harvested those codes live over the phone and seized access to the account before the call ended.

Observations from threat analysts

Austin Larsen, principal threat analyst at Google's Threat Intelligence Group, said the attackers were motivated by monetary calculations and targeted organizations they believed held sensitive data that would prompt payment to prevent exposure. "Really it's a money thing," Larsen said, adding that the groups tended to choose industries based on perceived financial return.

Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality ISAC, emphasized the role of the human element in the attacks. "Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," Clark said. He noted that human error continues to be a primary enabler of these compromises.

Scope and success unknown

Google said the malicious infrastructure listed in its report included dozens of sites and that the listed subdomains were likely used in attempted intrusions, while cautioning that they were not all successful. The public technical details did not identify which, if any, specific firms were successfully compromised. Google also noted that in some cases unnamed companies had paid ransoms to the attackers.

Responses from targeted firms

Several firms named in the intelligence review either declined to comment or did not immediately respond to requests for comment. KKR, Bain Capital, CME Group, TPG and Apollo declined to comment. Representatives for Blackstone, Bridgewater Associates and Moody's did not immediately reply to inquiries.

Industry implications

Experts say the campaign underscores that low-technology approaches - phone calls and social engineering - remain effective even against organizations with advanced security programs. The combination of convincing caller ID, urgent-sounding IT prompts and realistic-looking web pages allows attackers to bypass technical protections by exploiting routine human behavior.


Key points

  • Attackers used phone calls plus customized credential-harvesting websites to target employees at major private equity firms, market operators and ratings agencies.
  • Google identified the campaign and the group names Redact, Pink, Falcon and Helix; analysts said the attackers select targets based on financial motive.
  • The schemes relied on live harvesting of passcodes and multifunction authentication codes, enabling account takeover even when multifactor controls were in place.

Risks and uncertainties

  • It is unknown which specific companies, if any, were successfully compromised - the public technical data did not confirm successful intrusions.
  • Some companies reportedly paid ransoms in certain cases, but the identities of those paying entities were not disclosed.
  • The use of human-targeted social engineering means organizations with otherwise sophisticated defenses remain vulnerable, particularly across finance, legal, and ratings sectors.

Bottom line

The recent campaign shows that financially motivated attackers continue to blend simple, direct social engineering with carefully prepared online infrastructure to target high-value organizations in the financial sector. While investigators have cataloged the malicious domains and described the playbook, confirmation of successful compromises for specific firms has not been publicly established.

Risks

  • It is unclear which companies, if any, were successfully compromised; the public data did not confirm successful intrusions - affects financial services and private equity sectors.
  • Some firms reportedly paid ransoms in certain instances, but the companies were not named - creates uncertainty for corporate incident response and insurance in finance-related markets.
  • Reliance on social engineering means organizations with advanced technical defenses remain vulnerable, particularly law firms, ratings agencies and investment firms.

More from Stock Markets

Braveheart Bio Pops 68% in U.S. Debut After $382.5M IPO Aug 6, 2026 Protein Coffee Maker Javvy Weighs Sale as Protein Demand Climbs Aug 6, 2026 S&P Lowers Mosaic Outlook to Negative Citing Rising Input Costs and Weak Cash Flow Aug 6, 2026 Bper Banca Says It Is Prepared for Deals and a Buyback After Summer Aug 6, 2026 Bank of America Investment Banking Co-Head Mike Joo to Depart for External Role Aug 6, 2026