Hackers are increasingly using phone calls instead of malware to breach some of the largest financial institutions in the United States, according to new research from Google.

Google’s Threat Intelligence Group said several cybercriminal groups have spent the past month targeting investment firms, private equity companies and financial services providers by calling employees while posing as internal IT support staff. The attackers persuade victims to reveal login credentials or approve multi-factor authentication requests, giving them access to corporate systems.
Once inside, the hackers steal sensitive corporate data before demanding ransom payments to prevent the information from being leaked publicly. Google said the attacks are financially motivated and focus on organisations handling mergers and acquisitions, investments and other high-value financial transactions.
The company identified several hacker groups behind the campaign, including Redact, Falcon, Helix and Pink. Google believes the groups are linked to a broader cybercrime network known as UNC6671, which has evolved from previous extortion operations and continues to rely heavily on voice phishing, also known as “vishing.”
Investigators found that the attackers created more than 200 fake websites designed to closely resemble the login portals of targeted companies. During the calls, victims were directed to these fraudulent websites, where they unknowingly entered usernames, passwords and authentication codes.
The campaign targeted several of Wall Street’s biggest names, including Blackstone, Apollo Global Management, Bridgewater Associates, Bain Capital, KKR, TPG, CME Group and Moody’s, among others. Google did not disclose how many organisations were successfully breached or identify specific victims that paid ransoms.
The attacks demonstrate that human error remains one of the weakest links in corporate cybersecurity despite growing investment in advanced security technologies. Rather than exploiting software vulnerabilities, the hackers relied on trust and urgency to persuade employees to bypass established security procedures.
Google urged organisations to strengthen identity verification procedures for help desk requests, require additional authentication before resetting credentials and train employees to recognise voice phishing attempts. Security experts also recommend limiting the number of employees with privileged access and monitoring unusual login activity more closely.
The campaign reflects a broader evolution in cybercrime as attackers increasingly combine traditional phishing techniques with direct human interaction to bypass technical defences. As financial institutions continue to strengthen their digital infrastructure, cybersecurity experts expect voice-based social engineering attacks to become more frequent and more sophisticated.
Stay ahead of the Stories shaping our world. Subscribe to Impact Newswire and join our
WhatsApp Channel for updates on global tech, business, and innovation—all in one place.
Dive deeper into the future with the Cause Effect 4.0 Podcast, where we explore the ideas, trends, and technologies driving the global AI conversation.
Got a story to share? Contact Us to reach a global audience with Impact Newswire.
Emmanuel Abara Benson is a business journalist and editor covering artificial intelligence, global markets, and emerging technology.
He has previously worked with Business Insider Africa and Nairametrics, reporting on finance, startups, and innovation.
His work focuses on AI, digital economy, and global tech trends.
Discover more from Impact Newswire
Subscribe to get the latest posts sent to your email.



