Private equity vishing attacks draw Google warning over help-desk scams
Google says ransom-seeking groups shifted toward private equity and related firms, using calls and fake login pages to capture access codes.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
Private equity vishing attacks have become a focus for ransom-seeking cybercriminals, according to Google researchers, who said the campaign recently shifted towards buyout firms, law firms and financial ratings agencies. Reuters identified 72 malicious websites aimed at employees of prominent financial groups, but said it could not establish whether any of the attempted intrusions succeeded.
The campaign relies on phone-based social engineering rather than a novel technical exploit. Google said callers reached employees on personal mobile phones, posed as internal IT help-desk staff and claimed that an urgent passkey or multifactor-authentication update was required.
Targets were then directed to fraudulent web pages designed to resemble corporate login portals. According to Reuters, an employee entering a password could be prompted to supply a one-time authentication code during the call, allowing an attacker to take over the account before the call ended.
How do private equity vishing attacks work?
Vishing, or voice phishing, is a fraud technique in which an attacker uses a call or voice message to persuade a target to reveal information or approve access. In this campaign, the claimed IT request created urgency, while the spoofed website captured the password and multifactor code needed to enter an account.
- An attacker calls an employee’s personal number while impersonating a help-desk representative.
- The caller claims a security migration or authentication update must be completed immediately.
- The employee is sent to a lookalike login page and enters account credentials.
- The attacker obtains a multifactor code in real time and may use it to seize the account.
Google named groups operating under the labels Redact, Pink, Falcon and Helix. Its researchers said the groups may be linked to the broader UNC6671 collective, although their precise relationships remain unresolved. Google analyst Austin Larsen told Reuters that common infrastructure appeared to connect the operations, while cautioning that significant uncertainties remained.
Reuters analysed the web addresses listed in Google’s report using DomainTools and urlscan, finding tailored malicious subdomains linked to Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s, among others. The appearances in that data indicate targeting or attempted intrusion, rather than confirmed breaches.
Google did not publicly identify victim companies or say which organisations had paid ransoms. Reuters reported that the company said some unnamed businesses had paid, while Reuters could not determine which targets were successfully compromised. Several firms either declined comment or did not immediately respond, Reuters said.
Separately, Two Sigma said it had responded to an attempted vishing campaign aimed at it and other investment managers, and had no indication that its data or systems were affected, according to Fortune’s Bloomberg-sourced report. That statement does not establish an intrusion at any private-equity firm named in the malicious-domain analysis.
Google researchers recommended phishing-resistant authenticators and behavioural auditing of software-as-a-service activity to disrupt identity-focused attacks. The episode illustrates that code-based multifactor authentication can still be exposed when a user is persuaded to enter credentials and a live code into an attacker-controlled site.
This story draws on original reporting from Finextra Research.