Phone-Scam Hackers Now Target Wall Street’s Biggest Firms
Private equity firms have become the latest target of ransom-seeking hackers who use voice phishing to trick company employees, according to a new Google report.
The report withheld the names of the firms targeted. Reuters worked them out by feeding the 72 web addresses Google published into tools like DomainTools and urlscan, which surfaced subdomains matched to each company.
Inside the Vishing Campaign
In its latest report, Google Threat Intelligence Group (GTIG) said it continues to track a group known as UNC6671. The actors rely on voice phishing (vishing), posing as IT helpdesk staff pushing urgent security updates.
They often reach employees on personal mobile devices. The calls direct victims to spoofed login portals.
There, adversary-in-the-middle (AiTM) systems intercept credentials and multi-factor authentication (MFA) tokens. Once inside, the hackers run automated scripts to pull data from cloud services like Microsoft 365 and Okta.
"These operations uniformly leverage tailored IT helpdesk voice phishing (vishing), AiTM credential harvesting panels, and data theft from SaaS applications," the report read.
… Continue reading the full article at the original source below.



