Hackers targeted US private equity, other firms including Blackstone, CME, data shows


Hackers targeted US private equity, other firms including Blackstone, CME, data shows <br> Ransom-seeking&nbsp;hackers&nbsp;who&nbsp;use phone calls to compromise their victims&nbsp;targeted&nbsp;dozens of prominent United States&nbsp;financial institutions and&nbsp;other&nbsp;businesses over the past month, according to Google and internet intelligence&nbsp;data&nbsp;reviewed by Reuters. The&nbsp;data&nbsp;shows&nbsp;the&nbsp;hackers&nbsp;devised websites aimed at stealing passwords from employees of&nbsp;private&nbsp;equity&nbsp;firms&nbsp;and&nbsp;financial&nbsp;companies&nbsp;including&nbsp;Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG,&nbsp;CME&nbsp;Group,&nbsp;Clearlake Capital&nbsp;and Moody&#39;s, as well as&nbsp;other&nbsp;businesses. Google said in a blog post about the hacking campaign&nbsp;published on Thursday that the&nbsp;hackers&nbsp;operate under a range of names,&nbsp;including&nbsp;Redact, Pink, Falcon and Helix. Google declined to comment on Reuters findings. Its blog said in some cases companies, which it did not name, paid ransoms to the&nbsp;hackers. Reuters could not establish which companies the&nbsp;hackers&nbsp;successfully compromised. Read:&nbsp;US announces new visa restrictions targeting cybercrime, online scam networks Experts say the&nbsp;hackers&#39;&nbsp;use of low-tech tactics such as phone calls to target the financial industry illustrates how, despite sophisticated security programs and AI-driven threats, the oldest tactics still rank among the most effective. If successful, the hacks could compromise&nbsp;data&nbsp;of some of the biggest US&nbsp;private&nbsp;equity&nbsp;firms&nbsp;that provide capital to companies. &ldquo;Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for&nbsp;us,&rdquo; said Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, an industry information sharing and analysis group. &ldquo;That human element consistently is why this has exploded in the way it has,&quot; he said. KKR, Bain Capital,&nbsp;Clearlake Capital,&nbsp;CME, TPG and Apollo declined to comment.&nbsp;Blackstone, Bridgewater Associates and Moody&#39;s did not immediately respond to requests for comment. Hackers shift attention: Google In its blog post, Google &mdash; a unit of Alphabet &mdash; said the&nbsp;hackers&nbsp;had recently turned their attention to&nbsp;private&nbsp;equity, law&nbsp;firms&nbsp;and financial ratings agencies. Austin Larsen, the principal threat analyst at Google&rsquo;s Threat Intelligence Group, said the&nbsp;hackers&nbsp;generally&nbsp;targeted&nbsp;industries based on financial calculations, often successfully. &ldquo;Really, it&rsquo;s a money thing,&rdquo; Larsen said. &ldquo;They think that these&nbsp;firms&nbsp;or organisations have&nbsp;data&nbsp;sensitive enough that, if taken, they would pay to prevent it.&rdquo; Google did not identify any of the&nbsp;hackers&rsquo; targets by name. Reuters reverse-engineered many of the company-specific online traps&nbsp;used by the&nbsp;hackers&nbsp;by running the 72 malicious&nbsp;websites Google listed in its report through web intelligence platforms such as DomainTools and urlscan, which flagged malicious&nbsp;subdomains tailored to each firm. Speaking in general about the subdomains, Larsen said, &quot;They all were likely&nbsp;used in attempted intrusions&quot; though he cautioned, &quot;They were not all successful.&quot; Google said the&nbsp;hackers&nbsp;used &ldquo;meticulous&nbsp;social engineering tactics,&rdquo; reaching employees on their personal cellphones while pretending to call from their company&rsquo;s help desk, sometimes displaying the correct help desk phone number. Read More:&nbsp;Meta fixes massive AI assistant vulnerability after hackers seize Instagram accounts The&nbsp;hackers&nbsp;told their targets there was an urgent directive from IT to update their passkeys or multifactor authentication and steered the employees toward a booby-trapped website with domain names such as &ldquo;passkeyhelpdesk&rdquo; or &ldquo;secure-passkey.&rdquo; If an employee followed the instructions to enter their password, the&nbsp;hackers&nbsp;would harvest their fail-safe passcode &ndash; typically sent by text or generated by an app &ndash; live over the phone and hijack their account before the call terminated. Larsen said it was wrong to think of the tactic as particularly advanced. &quot;Sophisticated is not the right word,&quot; he said. &quot;It is just really effective.&quot; Shifting aliases Reuters was not able to reach the&nbsp;alleged&nbsp;hackers. Redact &mdash; which once went by the name Blackfile &mdash; said on its darknet website that its&nbsp;hackers&nbsp;&quot;are not politically or morally motivated&quot; and were &quot;not currently taking questions from the press.&quot;&nbsp;On its site, Falcon acknowledged being affiliated with Redact but said it had nothing to do with Helix or Pink. Larsen said it was unclear who the&nbsp;hackers&nbsp;were exactly or what their relationship was to one another. Although they went under different names, he said they appeared to be tied together by common infrastructure. &quot;There are still some unknowns here,&quot; he said. The hacking attempts, a few of which were earlier reported by Bloomberg, have caused a stir on Wall Street. For example, Point72 Asset Management told investors on Wednesday&nbsp;that it had been&nbsp;targeted&nbsp;by&nbsp;hackers, according to a source familiar with the matter. That source &ndash; and a second source familiar with the matter &ndash; said the ​hackers&nbsp;had also attempted to breach&nbsp;other&nbsp;hedge funds, ​including&nbsp;Two Sigma Investments and Citadel, whose names also appeared in the&nbsp;data&nbsp;reviewed by Reuters. Also Read:&nbsp;OpenAI models &#39;go rogue&#39; Two Sigma has not returned messages seeking comment. Citadel and Point72 declined to comment. A host of&nbsp;other&nbsp;firms&nbsp;were in the&nbsp;hackers&rsquo; crosshairs before they pivoted to financial institutions, according to Google&#39;s blog post and the&nbsp;data. The&nbsp;data&nbsp;shows&nbsp;that the cybercriminals built digital traps for more than 200 companies in the past five weeks alone,&nbsp;including&nbsp;the ride-hailing company Uber, online broker Zillow, and jeans brand Levi Strauss, as well as several law&nbsp;firms,&nbsp;including&nbsp;Paul Hastings and Greenberg Traurig. Uber, Zillow, Paul Hastings and Levi Strauss did not return messages seeking comment. In a statement, Greenberg Traurig said it &quot;did not have a&nbsp;data&nbsp;breach given the layers of security protocols we have in place to protect client&nbsp;data&nbsp;and the firm.&rdquo; It did not elaborate. <br> <img src="https://tribune.com.pk/story/2622584/hackers-targeted-us-private-equity-other-firms-including-blackstone-cme-data-shows" alt=" Hackers targeted US private equity, other firms including Blackstone, CME, data shows" width="100%">
Previous Post Next Post