Hackers Target Blackstone, Apollo and CME in Financial Sector Cyber Campaign 

Hackers Target Blackstone, Apollo and CME in Financial Sector Cyber Campaign 

Shivangi
Aug 7, 2026 12:26 PM IST
Category Cyber

Synopsis

Google says cybercriminals created 72 fake websites to steal employee credentials from private equity firms, exchanges and financial institutions, though no successful breaches have been confirmed.

01
Chapter one

Key Highlights

  • Hackers attacked top US financial firms.
  • Fake websites that use phone calls stole employee passwords and security codes. 
  • Google said that some businesses paid ransoms, but didn’t name them.
  • Data reviewed by Reuters showed that over the last five weeks, more than 200 companies received orders.

In data reviewed by Reuters, Google and internet intelligence data, over the past month, dozens of major US financial institutions and other businesses were targeted by ransom-seeking hackers using phone calls to trick victims

The data revealed that the hackers posted fake pages designed to capture passwords of workers at many private equity concerns and financial institutions, such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR and TPG as well as CME Group and Clearlake Capital and Moody’s,

The hackers operate under various names, such as Redact, Pink, Falcon and Helix, Google said in a blog post. Google, in a blog post, said it had seen some companies pay the ransom but provided no specific details. 

02
Chapter two

Basic Password Theft Methods

Security experts say the campaign is a clear demonstration that simple techniques, such as telephone calls never go out of fashion, even in the age of advanced cyber failure tests and AI.

According to Lee Clark, cyberthreat intelligence production manager at the Retail and Hospitality ISAC, a major way hackers operate easily is by getting guards to open the doors and let them in.

Age of News Hackers Target Financial Firms

Google said the hackers had recently begun targeting private equity firms, law firms and financial ratings agencies.

Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group said that the attackers select their industries based on financial calculations, often successfully. 

To do this, Reuters reviewed 72 malicious websites flagged by Google using web intelligence platforms like DomainTools and urlscan. The sites had login pages that impersonated the websites of specific companies, in order to steal the credentials of employees.

Larsen said the websites most probably were utilised for attacks, but not all of them were successful.

03
Chapter three

Fake Help-Desk Calls Used to Trick Employees

The hackers made unsolicited phone calls to company employees on their private mobile phones posing as helpline staff working for the company, according to Google. Some calls even showed the company help desk number correctly.

The callers said there was an urgent IT request to update passkeys or multi-factor authentication and sent employees to counterfeit websites called passkeyhelpdesk, secure-passkey and other similar names.

In the case of employee phone calls, hackers captured their one-time security codes as they spoke and gained access to their accounts before the call ended after employees entered their passwords. The method was “not especially sophisticated but very effective,” said Larsen.

04
Chapter four

Over 200 Companies Were Hit

On its own darknet site, Redact (previously going by the name Blackfile) said that its members seemed entirely morally apathetic and were not answering media queries.

It is still not known exactly who the hackers are or how the different groups connect, if at all, Larsen said, although they appear to use the same infrastructure. Notably, the attacks have caused enormous concern across Wall Street.

According to a source with knowledge of the issue, Point72 Asset Management informed investors on Wednesday that it had been hacked. The hackers were also said by two of the sources to have made unsuccessful attempts to penetrate Two Sigma Investments and Citadel, both of which are included in the data seen by Reuters.

Hackers created phishing websites targeting companies Reports reviewed by Reuters and Google’s blog also showed the hackers have registered sites that acted as phishing attacks against more than 200 companies during the previous five weeks.

The targets listed Uber, Zillow, Levi Strauss and law firms Paul Hastings and Greenberg Traurig. Greenberg Traurig did not disclose any information because it “did not suffer a data breach” thanks to security measures in place.

Source: Reuters 

Written by Shivangi

At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.