Low-Tech Phone Scams Breach Top US Private Equity and Financial Firms
Hackers bypassed advanced security by impersonating IT help desks to steal credentials from firms including Blackstone and KKR.
Ransom-seeking hackers have spent the last month targeting dozens of prominent U.S. financial institutions in a coordinated credential theft campaign. The attacks specifically focused on major private equity firms and ratings agencies, exploiting human psychology rather than software vulnerabilities to gain access to secure accounts.
The campaign targeted a roster of some of the world's most influential financial entities, including Blackstone, CME Group, Apollo Global Management, Bain Capital, KKR, TPG, Bridgewater Associates, and Moody's. The attackers did not rely on sophisticated malware. Instead, they used low-tech social engineering by calling employees on their personal mobile phones while impersonating IT help desk staff. Once trust was established, victims were directed to spoofed websites to "update" their passkeys or multi-factor authentication (MFA) settings, allowing the hackers to hijack accounts in real-time.
A Strategic Shift in Targeting
This campaign marks a deliberate pivot by threat actors toward private equity firms, law firms, and financial ratings agencies. This shift follows a broader pattern where attackers select industries based on the high financial incentives available for ransom payments. The hackers involved in these operations have operated under several aliases, including Redact, Pin, Falcon, and Helix.
This strategic targeting suggests that threat actors are increasingly prioritizing sectors where the potential for high-value payouts is greatest. By focusing on the intermediaries of global capital, these groups maximize their leverage during ransom negotiations, moving away from broad-spectrum attacks toward high-value, surgical strikes.
The Human Vulnerability
The breach of these specific firms is critical because they manage immense volumes of capital and highly sensitive financial data. The fact that low-tech phone scams were successful against some of the most sophisticated financial organizations in the world underscores a persistent weakness in human-centric security. While these firms employ advanced technical defenses, social engineering remains a primary vector that can bypass expensive security stacks by targeting the individual user.
What to Watch
As threat actors continue to refine their social engineering tactics, the industry is likely to see an increase in attacks targeting personal devices to circumvent corporate security perimeters. Security professionals are now monitoring whether these hijacked accounts have been used to exfiltrate proprietary data or if the attackers are currently positioning themselves for larger ransom demands. It remains to be seen if other sectors with high financial liquidity will be targeted using similar impersonation tactics, as the success of this campaign provides a blueprint for bypassing MFA through psychological manipulation.