Hackers Target Major Wall Street Firms in Large-Scale Phishing Campaign, Google Says
A large-scale cyber campaign targeting some of the biggest names in the U.S. financial industry has been uncovered, with Google's Threat Intelligence Group identifying a coordinated effort that relied on fake IT support calls and phishing websites instead of sophisticated malware.
The campaign targeted employees at investment firms, hedge funds, law firms, and financial services companies by tricking them into handing over login credentials and multi-factor authentication (MFA) codes.
Summary: Google says hackers targeted more than 200 companies using fake IT help desk calls and phishing websites, highlighting the growing threat of social engineering attacks against the financial sector.
Which Companies Were Targeted?
The campaign targeted employees at several high-profile organizations, including:
-
Blackstone
-
Bridgewater Associates
-
Apollo Global Management
-
Bain Capital
-
KKR
-
TPG
-
CME Group
-
Moody's
-
Clearlake Capital
Additional reported targets included Point72 Asset Management, Citadel, Two Sigma Investments, Uber, Zillow, Levi Strauss, Paul Hastings, and Greenberg Traurig.
How Did the Attack Work?
Rather than exploiting software vulnerabilities, the attackers focused on manipulating employees.
Google said the hackers typically:
-
Called employees on their personal mobile phones while pretending to be corporate IT support.
-
In some cases, spoofed legitimate company help desk phone numbers.
-
Claimed employees needed urgent updates to passkeys or multi-factor authentication.
-
Directed victims to fake login portals with names such as "passkeyhelpdesk" and "secure-passkey."
-
Captured usernames, passwords, and one-time authentication codes entered by victims.
-
Used the stolen credentials immediately before authentication sessions expired.
Direct Answer: The attackers relied primarily on social engineering, convincing employees to voluntarily provide login credentials instead of hacking company systems directly.
Google Identifies Multiple Hacker Groups
Google said the campaign involved threat actors operating under several names, including:
-
Redact
-
Pink
-
Falcon
-
Helix
While the exact relationship between the groups remains unclear, Google believes they likely share common infrastructure and tactics.
The company also identified 72 malicious phishing websites, while estimating that infrastructure was created to target more than 200 companies over approximately five weeks.
Why Are Financial Firms Being Targeted?
Google's Threat Intelligence Group believes the motivation is largely financial.
Private equity firms, hedge funds, law firms, and ratings agencies often possess confidential investment, legal, and financial information. Attackers may view these organizations as more likely to pay ransom or extortion demands to prevent sensitive data from being exposed.
Cybersecurity experts noted that the campaign reflects a broader shift away from highly technical attacks toward exploiting human behavior.
Human Error Remains a Cybersecurity Risk
Security professionals say modern organizations have significantly improved their technical defenses, making employees an increasingly attractive target.
Lee Clark of the Retail and Hospitality ISAC said cybercriminals are increasingly choosing to manipulate people rather than attack systems directly, because the human element often remains the easiest path into corporate networks.
Several targeted companies, including KKR, Bain Capital, CME Group, TPG, Apollo, Citadel, and Point72, declined to comment. Greenberg Traurig said it did not experience a data breach, while Reuters was unable to confirm whether several other organizations had suffered successful intrusions.
The campaign underscores how phishing and social engineering continue to pose serious risks even for organizations with advanced cybersecurity defenses, reinforcing the importance of employee awareness and strong authentication practices.

