Tech
EN AZ
Google says hackers are calling financial firm employees to hack and extort victims

Google says hackers are calling financial firm employees to hack and extort victims

techcrunch.com 06.08.2026 23:40 24 baxış
Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.

🚨 Flash Sale 🚨 Get $100 off your Disrupt 2026 ticket Get $400 off your Disrupt 2026 ticket: REGISTER NOW. Close TechCrunch Desktop Logo TechCrunch Mobile Logo LatestStartupsVentureAppleSecurityAIAppsDisrupt 2026 EventsPodcastsNewsletters SearchSubmit Site Search Toggle Mega Menu Toggle Topics Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture More from TechCrunch Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us Image Credits:Michael Nagle/Bloomberg / Security Google says hackers are calling financial firm employees to hack and extort victims Lorenzo Franceschi-Bicchierai 12:40 PM PDT · August 6, 2026 Even in the age of AI-powered autonomous cyberattacks, the crude, tried and tested hacking techniques of tricking victims into doing things they shouldn’t are still producing great results. Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims with the threat of publishing it, Google’s security researchers wrote in a report on Thursday.

The company did not name the victims, but reported that among them there are leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. The hacking groups, which Google dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique to break into those firms: phone calls to employees’ personal cellphones in which the hackers pretend to be co-workers or IT helpdesk staffers, during which they try to trick targets into entering their credentials and multi-factor codes on spoofed websites, according to Google. In cybersecurity parlance, this technique is known as voice phishing, or vishing.

Some of the groups identified by Google run websites where they publicize their hacks and threaten to leak the stolen data as a way to extort the victims into paying a ransom, a common strategy among cybercriminals. Image Credits:Google / “We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” read one of the sites.

But it’s unclear if they are affiliates, splinter groups, or they all use the same Phishing-as-a-Service infrastructure. var playerInstance_jwplayer_6a752756005b7 = jwplayer( "jwplayer_6a752756005b7" ); playerInstance_jwplayer_6a752756005b7.setup(); “We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” read the report. Contact Us Do you have more information about these data breaches? We’d love to hear from you.

From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. According to Google, the hacking groups have also previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies with the goal of stealing “valuable intellectual property, software source code, or sensitive VIP client data.” More recently, the hackers have targeted legal and financial organizations such as private equity firms. Google said that one cryptocurrency wallet associated with one of the hacking groups received around $10 million in bitcoin in the first few months of this year, and that the hackers usually demand from $750,000 to $3 million from victims.

Laurie Bischel, a spokesperson for CME Group, declined to comment. Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s, and TPG did not respond to a request for comment. Topics cybercrime, cybersecurity, Google, hackers, hacking, phishing, Private Equity, Security, venture capital, vishing When you purchase through links in our articles, we may earn a small commission.

Extract — continue reading at the source.

Read full story