Breaking news

Google Warns Of Vishing Campaign Targeting Financial Firms

Cybercriminals are increasingly relying on a simple tactic to breach major financial institutions: convincing employees to hand over their own login credentials.

In a new report, Google said several hacking groups have been targeting large financial and investment firms in the United States through voice phishing, or “vishing”, before stealing sensitive corporate data and using it to extort victims.

Employees Are The Primary Target

According to Google’s researchers, attackers contact employees on their personal mobile phones while posing as colleagues or IT support staff. Victims are then directed to fake websites, where they are tricked into entering login credentials and multi-factor authentication codes.

Google tracks the groups under the names Falcon, Helix, Pink and Redact, although researchers believe they may be linked to a broader threat cluster known as UNC6671.

Some of the groups operate leak websites, where they threaten to publish stolen data unless companies agree to pay a ransom.

Financial Sector In The Spotlight

While previous attacks targeted industries including manufacturing, healthcare, insurance, technology and hospitality, Google said the hackers have increasingly shifted their focus to financial institutions and law firms.

Researchers believe organisations involved in mergers, acquisitions and capital markets are particularly attractive targets because of the highly confidential information they hold.

Google estimated that one cryptocurrency wallet linked to the operation received around $10 million in bitcoin during the first few months of the year. Ransom demands typically range from $750,000 to $3 million.

The report highlights that despite rapid advances in AI-driven cyberattacks, traditional social engineering techniques remain among the most effective ways for attackers to gain access to corporate networks.

Google Sets New Android App Rules To Cut Memory Use

Google is introducing new quality requirements for Android apps as developers face tighter constraints on device memory and broader hardware supply pressures.

The company announced two new requirements this week. One focuses on reducing apps’ memory use and improving code efficiency, while the other requires apps to restore users’ sign-in status when they move to a new Android device.

Google Sets New Memory Performance Rules

Google said the mobile industry is facing “significant hardware supply constraints that are altering device memory availability,” which could affect app performance and the user experience.

Under the new rules, developers will need to meet thresholds covering areas including dynamic memory and bitmap usage. Additional code optimisation requirements are designed to reduce slowdowns and crashes linked to excessive resource use.

Google is also rolling out tools that alert developers when their apps exceed the new limits. More diagnostic features are planned later this year, including deeper analysis through Android’s Memory Limiter, which restricts excessive memory use.

Developers have until February 2027 to comply with the new standards, according to Google’s Android Developer documentation.

Zero-Tap Sign-In Requirement Starts In 2027

A separate requirement will apply to all apps distributed through Google Play. By April 2027, apps that use optional or mandatory sign-ins must automatically restore a user’s sign-in state when they move between Android devices.

The feature will rely on Android’s Restore Credentials API, which is designed to transfer sign-in credentials during device migration without requiring users to log in again.

Google said the new standards are intended to help developers maintain app performance and simplify device transitions as device specifications and memory availability change.

The Future Forbes Realty Global Properties
eCredo
Aretilaw firm
Uol

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter