U.S. — Google disclosed a report on Thursday detailing ongoing cyberattacks against prominent U.S. financial institutions and other major businesses. The campaign utilized sophisticated social engineering tactics, including fake helpdesk websites and voice phishing, to extort ransoms from targeted organizations.

The hackers built custom websites to steal passwords from staff at private equity firms and financial companies. Hackers called employees at targeted businesses, posing as company help desks, to obtain sensitive data. The attackers manipulated caller ID systems to display the legitimate internal help desk phone number while calling employees on their personal cellphones.

The fake websites prompted employees to enter their primary passwords, and the hackers harvested temporary passcodes live over the phone while speaking to the employee. The attackers hijacked the victim’s corporate account immediately before ending the call.

The targeted firms included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s. Anonymous sources confirmed that hackers also targeted hedge funds Two Sigma Investments and Citadel. The attackers pursued ride-hailing company Uber, online real estate broker Zillow, and clothing brand Levi Strauss.

The hackers targeted law firms Paul Hastings and Greenberg Traurig. Greenberg Traurig released a statement confirming their security protocols successfully protected client data and prevented a data breach. Point72 Asset Management informed investors on Wednesday about a recent attack attempt.

The cybercriminals built digital traps for more than 200 companies during the past five weeks. Google identified several aliases the hackers utilize, including Redact, Pink, Falcon, and Helix. Google researchers stated that the different groups may all be part of a larger umbrella collective tracked under the name UNC6671.

One cryptocurrency wallet associated with one of the hacking groups received around $10 million in bitcoin in the first few months of this year. The hackers usually demand from $750,000 to $3 million from victims. Some of the groups run websites where they publicize their hacks and threaten to leak stolen data to extort victims into paying a ransom. Several unnamed companies were successfully breached and paid ransoms. Reuters could not establish which companies the hackers successfully compromised.

Austin Larsen, principal threat analyst at the Google Threat Intelligence Group, said the attacks are driven by financial incentives. "Really, it’s a money thing," Larsen said. He explained that criminals exploit the assumption that targeted entities possess data valuable enough to warrant payment.

"They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it," he said. Larsen noted that the technical complexity of the attacks was less important than their success rate. "Sophisticated is not the right word," he said. "It is just really effective."

Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, said the strategy bypasses technical defenses by exploiting human behavior. "Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," Clark said. He attributed the rise in such incidents to this specific vulnerability. "That human element consistently is why this has exploded in the way that it has," Clark said.

KKR, Bain Capital, Clearlake Capital, CME, TPG, Apollo, Point72, and Citadel declined requests for comment. Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG did not respond to a request for comment.

The FBI’s 2025 Internet Crime Report shows cyber-enabled crimes defrauded Americans of nearly $21 billion, with cryptocurrency and artificial intelligence-related complaints among the costliest. Google researchers wrote that concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands. The goal of the attacks was to steal valuable intellectual property, software source code, or sensitive VIP client data.

Google said the hacking groups have previously targeted large companies in the manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors. PureSource News previously reported on researchers documenting Silent Ransom Group cyberattacks.

Why It Matters

The campaign targets over 200 companies, including major financial institutions and law firms, to steal sensitive data for ransom demands ranging from $750,000 to $3 million. By manipulating caller ID systems and using fake websites to bypass technical defenses, the attackers exploit human behavior rather than software vulnerabilities. This strategy has already resulted in successful breaches and payments by unnamed organizations, showing a shift toward high-leverage extortion based on the perceived value of corporate data.