Phone calls from people posing as corporate help-desk staff were used in a ransom campaign targeting some of the biggest names in US finance. The callers paired company-specific fraudulent websites with instructions intended to make employees surrender passwords and additional security codes.
The businesses placed in the hackers’ crosshairs included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s. The websites were tailored to individual companies and designed to capture employee login credentials.