Cybercriminals are increasingly relying on a simple tactic to breach major financial institutions: convincing employees to hand over their own login credentials.
In a new report, Google said several hacking groups have been targeting large financial and investment firms in the United States through voice phishing, or “vishing”, before stealing sensitive corporate data and using it to extort victims.
Follow THE FUTURE on LinkedIn, Facebook, Instagram, X and Telegram
Employees Are The Primary Target
According to Google’s researchers, attackers contact employees on their personal mobile phones while posing as colleagues or IT support staff. Victims are then directed to fake websites, where they are tricked into entering login credentials and multi-factor authentication codes.
Google tracks the groups under the names Falcon, Helix, Pink and Redact, although researchers believe they may be linked to a broader threat cluster known as UNC6671.
Some of the groups operate leak websites, where they threaten to publish stolen data unless companies agree to pay a ransom.
Financial Sector In The Spotlight
While previous attacks targeted industries including manufacturing, healthcare, insurance, technology and hospitality, Google said the hackers have increasingly shifted their focus to financial institutions and law firms.
Researchers believe organisations involved in mergers, acquisitions and capital markets are particularly attractive targets because of the highly confidential information they hold.
Google estimated that one cryptocurrency wallet linked to the operation received around $10 million in bitcoin during the first few months of the year. Ransom demands typically range from $750,000 to $3 million.
The report highlights that despite rapid advances in AI-driven cyberattacks, traditional social engineering techniques remain among the most effective ways for attackers to gain access to corporate networks.







