Wall Street ransom plot relies on simple phone scams

TL;DR Summary
Hackers are using basic social-engineering to trick employees at major Wall Street firms into revealing passwords and MFA codes by spoofing internal IT helpdesk numbers and directing staff to fake passkey websites. The campaign targeted over 200 companies in about five weeks, including Blackstone, KKR, Apollo Global Management, Bain Capital, CME Group and others; some victims reportedly paid ransoms while many intrusions were blocked. The attackers use voice calls and booby-trapped sites to harvest credentials and hijack accounts in real time, illustrating a persistent human-factor vulnerability despite high-tech defenses.
- Hackers use simple phone trick to hold Wall Street giants hostage in ransom plot: report New York Post
- Major Wall Street firms targeted in attempted cyberattacks, sources say Reuters
- Google says hackers are calling financial firm employees to hack and extort victims TechCrunch
- When a hedge fund boss calls to offer you a job, it may not be them eFinancialCareers
- Big US hedge funds targeted by wave of cyber attacks Financial Times
Reading Insights
Total Reads
0
Unique Readers
6
Time Saved
5 min
vs 6 min read
Condensed
92%
1,108 → 89 words
Want the full story? Read the original article
Read on New York Post