Aug 11 / Latest News

Google Warns of Surge in Vishing Attacks Targeting Private Equity and Financial Firms

As financial services brace for increasingly sophisticated AI‑powered cyber threats, Google researchers say dozens of firms have instead been hit by low‑tech attacks relying on phone calls. Recent campaigns have targeted private equity firms, financial ratings agencies, and law firms, with attackers impersonating IT helpdesk staff to trick employees into handing over credentials.

While Google did not name victims, Reuters reports that Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG have all been targeted in recent months. Google has identified several hacking groups linked to the collective UNC6671, which remain connected and typically demand ransoms ranging from $1 million to $3 million.

The attackers rely heavily on vishing—calling employees on their personal phones and posing as IT staff conducting urgent security migrations. Victims are directed to spoofed login portals designed to capture credentials and multi‑factor authentication codes. Despite the simplicity of the technique, Google says the groups have had notable success, with ransom payments averaging around $750,000 among victims who choose to pay.

Google identified one cryptocurrency wallet associated with a linked hacking group that received roughly $10 million in bitcoin this year, underscoring the financial scale of the campaign. The company warns that organizations should prioritize phishing‑resistant authentication methods and behavioral SaaS auditing to disrupt these identity‑centric attacks.

As attackers blend low‑tech social engineering with high‑value targets, Google’s findings highlight that even the most sophisticated firms remain vulnerable when employees can be manipulated over the phone.