A phone call used to be the safest form of communication in a company. That has changed. Google’s security researchers say hackers are calling financial firm employees to hack and extort victims, and the technique is working against some of the most well-protected companies in the world.
This is not a theoretical warning. Google published a report on Thursday describing a real, ongoing campaign against large financial and investment firms in the United States. No advanced malware. No zero-day exploits. Just a phone, a convincing voice, and a fake login page.
What Google Actually Found
Google’s Threat Intelligence Group tracked several hacking groups running the same playbook against different targets. The company gave these groups internal names: Falcon, Helix, Pink, and Redact. Reuters later reported, based on Google and internet intelligence data, that the targeted firms include major private equity names such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.
None of these firms have confirmed a breach. A CME Group spokesperson declined to comment, and the other named companies did not respond to requests for comment. So while the targeting is confirmed, the actual outcome at each firm is not fully known.
What is clear is the method. Hackers are calling financial firm employees to hack and extort victims by posing as someone the employee already trusts, usually a coworker or a member of IT support.
How the Vishing Scam Actually Works
The technique has a name in the security world: vishing, short for voice phishing. It is simple, and that simplicity is exactly why it works.
Here is the general pattern Google described:
- An employee gets a call on their personal cellphone, not their work line.
- The caller sounds calm, professional, and familiar with company terms or internal processes.
- The caller claims there is a login issue, a security check, or an urgent IT request.
- The employee is guided to a fake website that looks like a normal company login page.
- The employee types in their username, password, and multi-factor authentication code.
- The hackers now have real, working access to company systems.
That last step is the dangerous part. Multi-factor authentication is supposed to stop this kind of attack. But if the victim types the code into a fake site in real time, the hackers can use it immediately before it expires. This is why Google says hackers are calling financial firm employees to hack and extort victims instead of trying to brute force passwords or exploit software bugs.
Why Financial and Legal Firms Are the Target
Google’s researchers made an interesting observation about who these groups are now going after. The hackers appear to be shifting focus toward firms involved in mergers, acquisitions, capital deployment, and litigation.
That is not random. Deal documents, litigation records, and investor data are exactly the kind of information a company would pay a lot of money to keep private. A leak during an active merger negotiation could tank a deal or trigger lawsuits. That leverage is the entire business model behind why hackers are calling financial firm employees to hack and extort victims in this particular sector right now.
Google also noted that these same groups have previously gone after manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality companies. Financial firms are simply the latest and most lucrative target.
The Money Behind the Attacks
Google’s report included some numbers worth paying attention to. One cryptocurrency wallet linked to a single hacking group received around 10 million dollars in bitcoin during the first few months of this year alone. Ransom demands from these groups typically range from 750,000 dollars to 3 million dollars per victim.
Some of these groups run public extortion websites where they post evidence of a breach and threaten to publish stolen files unless the company pays. It is a pressure tactic designed to force a fast decision before a company has time to investigate what was actually stolen fully.
Why This Keeps Working Even at Sophisticated Companies
I have spent enough time around corporate security teams to know the truth: technical defenses are usually stronger than human defenses. A company can spend millions on firewalls, endpoint detection, and network monitoring, and still get breached because one employee picked up the phone at the wrong moment.
Vishing works because it exploits trust, not code. An employee who would never click a suspicious email link might still believe a calm voice on the phone claiming to be from the internal help desk. The fact that Google says hackers are calling financial firm employees to hack and extort victims at firms with massive security budgets shows that the human layer is still the weakest.
There is also a psychological trick at play. Urgency. The caller usually implies something needs to happen right now: a locked account, a suspicious login, a compliance deadline. That pressure short circuits normal caution.
What Employees Should Actually Do
If your company handles sensitive financial, legal, or client data, here is practical advice based on how these attacks actually unfold.
Never enter credentials after an unsolicited call.
If someone calls claiming to be IT or a coworker and asks you to log into anything, hang up and contact IT through a known internal channel, not a number or link they gave you.
Verify the caller independently.
Call back using a number from your company directory, not a number the caller provided. Real IT departments understand this and will not be offended.
Treat personal cellphone calls about work systems with suspicion.
Google specifically noted that hackers are calling financial firm employees to hack and extort victims through personal numbers, which bypasses normal corporate phone security.
Use hardware security keys where possible.
Codes typed into a website can be phished. Physical security keys that require a device to be present are much harder to defeat with a phone call alone.
Report the call even if you did not fall for it.
A single suspicious call can be the first sign of a coordinated campaign against your entire company.
What This Means for the Financial Industry
The bigger picture here is uncomfortable. Financial firms, particularly private equity and investment firms, sit on enormous amounts of confidential deal information. As Google says, hackers are calling financial firm employees to hack and extort victims; it signals that this industry has become a preferred target, not just an occasional one.
Security teams at these firms will likely need to rethink employee training. Traditional phishing awareness programs focus heavily on suspicious emails. Fewer programs prepare employees for a confident, well-informed voice on the other end of a phone call.
Regulators and compliance officers may also start asking harder questions about how firms verify identity internally, especially for employees who handle deal-related or client data.
A Fair Look at the Uncertainty Here
It’s worth being honest about what is confirmed and what isn’t. Google confirmed the tactics, the group names, and the financial figures. Reuters reported the names of the targeted firms based on data review, not direct confirmation from the firms themselves. None of the named companies has publicly confirmed that a breach actually succeeded.
So while it is accurate to say Google says hackers are calling financial firm employees to hack and extort victims, it would be inaccurate to claim every named firm was definitely compromised. Targeting and successful breach are two different things, and the distinction matters.
This story is a reminder that not every serious cyberattack requires cutting-edge hacking skills. Sometimes it just requires a phone, patience, and a convincing script. Google says hackers are calling financial firm employees to hack and extort victims because it works, and it will likely keep working until companies treat phone-based social engineering with the same seriousness as email phishing.
For employees at financial and legal firms especially, the safest habit right now is simple skepticism. If a call feels slightly off, it probably is.
