Hackers Target Blackstone, KKR, Apollo and Wall Street Firms in Vishing Campaign
- 13 minutes ago
- 2 min read
Hackers are targeting some of the biggest names in private equity and finance with a sprawling social engineering campaign that shows attackers do not need sophisticated malware when they can simply convince employees to hand over access.
According to Google threat intelligence and internet infrastructure data reviewed by Reuters, attackers created at least 72 malicious websites designed to steal credentials from employees at firms including Blackstone, Apollo Global Management, KKR, Bain Capital, Bridgewater Associates, TPG, CME Group, Clearlake Capital and Moody's.
The campaign relies heavily on voice phishing, or vishing. Attackers impersonate corporate help desks, call employees on their personal phones and claim an urgent security action is required, such as updating a passkey or multifactor authentication setting.
Victims are then directed to convincing credential-harvesting websites with names designed to resemble legitimate IT services. Attackers can capture passwords and MFA codes in real time, allowing them to potentially take control of accounts before the phone call ends.
Google said the groups behind the activity operate under several names, including Redact, Pink, Falcon and Helix, although the exact relationships between the groups remain unclear.
“Really, it’s a money thing,” Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, said. “They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.”
The attackers have reportedly expanded their focus toward private equity firms, law firms, hedge funds and financial ratings agencies. Infrastructure analyzed by Reuters suggested cybercriminals created traps targeting more than 200 companies over roughly five weeks, including Uber, Zillow, Levi Strauss and several major law firms.
Emma Stevens, Threat Intelligence Researcher at Bitsight, said the campaign demonstrates why human verification remains critical even when companies deploy advanced cybersecurity defenses.
“The reported targeting of private equity firms and other financial organizations is a reminder that sophisticated attacks do not always require sophisticated technology. Attackers are using help desk targeted vishing, credential-harvesting sites and real-time MFA theft because a convincing phone call can still be enough to bypass even strong technical controls.”
Stevens said employees should independently verify unexpected requests involving credentials, payments or authentication rather than trusting caller ID.
“Caller ID is no longer reliable due to spoofing, so companies should not rely on voice alone for authentication. Password and MFA resets should require independent, out-of-band verification, and firms should prioritize phishing-resistant MFA, including FIDO2 security keys or passkeys.”
The campaign highlights a growing security challenge for financial institutions: attackers are increasingly targeting the people operating security systems rather than attempting to defeat the technology itself.


