US private equity firms including Blackstone, Apollo Global Management, KKR, Bain Capital, TPG and Clearlake Capital have been among more than 200 companies targeted in a recent cyberattack campaign, according to a report by Reuters.
The report cites data from Google and internet intelligence researchers as revealing that the campaign has focused on stealing employee credentials through highly targeted social-engineering attacks, highlighting the vulnerability of financial firms even as they invest heavily in more sophisticated cybersecurity systems.
Other financial institutions identified among the targets include Bridgewater Associates, CME Group and Moody’s, while hedge funds including Point72 Asset Management, Two Sigma Investments and Citadel were also reportedly targeted.
Google’s Threat Intelligence Group said the hackers have recently shifted their attention towards private equity firms, law firms and financial ratings agencies, with the attackers apparently selecting targets based on their ability and willingness to pay a ransom.
The campaign has operated under several aliases, including Redact, Pink, Falcon and Helix. Google said the groups appear to share infrastructure, although their exact relationships and identities remain unclear.
Rather than relying on highly sophisticated technical exploits, the attackers have used phone calls and impersonated corporate IT help desks to persuade employees to surrender credentials.
Targets were contacted on personal mobile phones and told that they needed to urgently update passkeys or multi-factor authentication credentials. In some instances, the attackers were able to make the incoming call appear to originate from the company’s genuine help desk number.
Employees were then directed to fraudulent websites designed to resemble corporate authentication or support pages.
If a target entered their password, the hackers could capture the one-time authentication code generated by an app or sent via text message while remaining on the phone with the victim. This allowed them to take control of the account before ending the call.
Austin Larsen, a principal threat analyst at Google’s Threat Intelligence Group, said the approach was less technically sophisticated than it was effective.
The campaign demonstrates how the human element can remain a significant vulnerability for private equity firms, which hold sensitive information on portfolio companies, investment strategies, transactions and financial data.
Google identified 72 malicious websites associated with the campaign, while analysis by Reuters found that many were customised for individual companies.
The attackers are understood to have created digital traps targeting more than 200 businesses over a five-week period. Targets extended beyond financial services to include Uber, Zillow, Levi Strauss and law firms such as Paul Hastings and Greenberg Traurig.
The campaign appears to have evolved over time, with the attackers initially targeting a broad range of businesses before increasing their focus on financial institutions.
Google said some companies had paid ransoms following successful attacks, although it was not possible to establish which organisations had been compromised or paid.
Several of the private equity firms named in the data reportedly declined to comment, while others did not immediately respond to requests for information.