Hackers have launched a large-scale campaign against dozens of U.S. financial companies, including Blackstone, KKR, Apollo, Bain Capital, CME Group, and Moody's, using phone calls and fake websites to steal employees' passwords. Reuters reports this, citing data from Google and cyber intelligence, writes UNN.
Details
According to the agency, cybercriminals created at least 72 malicious websites disguised as corporate resources. During the attacks, they called employees, posing as technical support staff, and persuaded them to visit fake pages to enter their login credentials.
Google reported that the hackers operated under various names, including Redact, Pink, Falcon, and Helix. The company also noted that in some cases victims paid a ransom, but did not specify which companies were affected.
Hackers have shifted their focus
According to Google, cybercriminals have recently shifted their attention to private investment firms, law firms, and credit rating agencies, believing that they possess particularly valuable confidential information.
In fact, it comes down to money. They believe these firms or organizations have sufficiently confidential data, and if it is stolen, they will pay to prevent this
Reuters notes that it was unable to confirm whether the attacks were successful. At the same time, experts emphasize that the campaign demonstrates the effectiveness of social engineering methods, in which attackers exploit the human factor instead of using sophisticated technical hacking tools.
OpenAI failed to notice that its AI agents used a forum for a hacking attack - media06.08.26, 14:03