Google says hackers are calling financial firm employees to hack and extort victims
Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.
Google's security researchers have reported that hackers are targeting large financial and investment firms in the United States, including prominent private equity firms, through a tactic known as voice phishing, or "vishing." The hackers impersonate coworkers or IT staff via phone calls, attempting to trick employees into entering their credentials and multi-factor codes on spoofed websites.
This age-old hacking technique still proves effective in stealing sensitive data and extorting victims with the threat of publishing it. The hacking groups, identified as Falcon, Helix, Pink, and Redact, run websites where they publicize their hacks and threaten to leak stolen data to extort victims into paying ransom. These groups, which may belong to a larger collective tracked by Google as UNC6671, are targeting various industries, including manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality, as well as legal and financial organizations. The hackers demand ransom ranging from $750,000 to $3 million from their victims.
Brief written by urgent.news from TechCrunch's own syndicated text. Machine-written — it may contain errors, so check the original before relying on it.