Unknown hacking groups are targeting major financial and investment firms in the United States, using social engineering tactics to steal sensitive data and threaten to publish it unless victims pay a ransom, Google security researchers said in a report on Thursday.
The researchers said the attacks demonstrate that despite the growing use of artificial intelligence in cyberattacks, traditional hacking techniques remain highly effective.
Google said the groups, which it identified as Falcon, Helix, Pink and Redact, are targeting employees through phone calls to their personal mobile devices.
The attackers reportedly pose as co-workers or IT helpdesk personnel and attempt to trick employees into entering their login credentials and multi-factor authentication codes on fraudulent websites.
“We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” read one of the sites.
“Respond promptly and in good faith, and the matter is resolved without further incident.”
Google researchers said the groups may be part of a larger hacking collective that the company tracks as UNC6671.
However, it remains unclear whether they operate as affiliates, splinter groups, or independently use the same phishing-as-a-service infrastructure.
