Ransom-seeking hackers targeted dozens of U.S. financial institutions over the past month. The campaign uses voice phishing to impersonate IT help desk staff. Attackers trick employees into revealing credentials on fraudulent login websites.

A Google report detailed the operation's use of password-stealing sites. The campaign targeted employees at major private equity firms, exchanges, and ratings agencies. Specific targets included Blackstone, CME Group, Apollo Global Management, KKR, TPG, Bridgewater Associates, and Moody's.

These social engineering tactics bypass technical defenses by exploiting human vulnerabilities. Hackers aim to gain access to sensitive corporate data for extortion purposes.