Hackers use simple phone trick to hold Wall Street giants hostage in ransom plot: report

Ransom-seeking hackers targeted dozens of prominent US financial institutions and other major businesses over the past month, according to a report.Google disclosed the ongoing cyberattacks earlier this week, with Reuters reporting that the targeted firms included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.The cybercriminals did their hacking the old fashioned way, simply calling up employees at those businesses, posing as company help desks, and then getting their unwitting targets to give up sensitive data, Google shared.The hackers also built custom websites to steal passwords from staff at private equity firms and financial companies, Reuters reported.Google indicated the attackers recently shifted their focus toward financial titans, law firms and financial ratings agencies — entities that tend to manage massive pools of capital, making them alluring targets.Austin Larsen, principal threat analyst at the Google Threat Intelligence Group, explained the financial calculations driving the attackers.“Really, it’s a money thing,” Reuters quoted him as saying.“They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.”Google noted some unnamed companies have already paid ransoms to the attackers.
The hackers’ technique for breaching corporate networks is known as “social engineering.”Social engineering involves manipulating individuals into revealing confidential information rather than using technical software exploits.The hackers call employees directly on their personal cellphone and pretend to represent the corporate information technology help desk, Google said.The attackers are allegedly able to manipulate caller ID systems to display the legitimate internal help desk phone number, building immediate trust with the victim.The attackers instruct workers to update their passkeys or multifactor authent...