Hackers have launched a sophisticated campaign targeting over 200 financial companies, including major firms like Blackstone and Apollo Global Management, by impersonating IT support staff. The attackers created fake IT help desks to trick employees into divulging their multi-factor authentication credentials. This tactic has allowed the hackers to breach the security of several high-profile organizations, with some companies even paying ransoms to mitigate the damage. The campaign, tracked by the Google Threat Intelligence Group, operates under various names such as Redact, Pink, and Helix, and has been linked to the UNC667 threat group1. The success of this campaign highlights the evolving nature of cyber attacks, which now often rely on social engineering tactics to bypass traditional security measures. This development matters to security practitioners because it underscores the need for robust employee training and awareness programs to prevent such breaches, which can have significant downstream regulatory and supply-chain implications.
Hackers Impersonate IT Support to Breach Leading Financial Companies
⚡ High Priority
Why This Matters
A breach involving Google signals evolving attack methods — watch for downstream regulatory and supply-chain effects.
References
- SecurityAffairs. (2026, August 7). Hackers Impersonate IT Support to Breach Leading Financial Companies. *SecurityAffairs*. https://securityaffairs.com/196800/security/hackers-impersonate-it-support-to-breach-leading-financial-companies.html
Original Source
SecurityAffairs
Read original →