PE firms targeted in wave of social-engineering cyberattacks
More than 200 companies, including US private equity firms such as Blackstone, Apollo Global Management, KKR, Bain Capital, TPG and Clearlake Capital, have been targeted in a recent cyberattack campaign focused on stealing employee credentials through social engineering.
Private equity firms, including Blackstone, Apollo Global Management, KKR, Bain Capital, and TPG, along with Clearlake Capital, were among more than 200 companies targeted in a recent cyberattack campaign. The campaign, detailed in a Reuters report citing data from Google and internet intelligence researchers, focused on stealing employee credentials through social-engineering tactics. This highlights a significant vulnerability for financial institutions, despite their investments in advanced cybersecurity. Other financial institutions targeted included Bridgewater Associates, CME Group, and Moody’s, while hedge funds such as Point72 Asset Management, Two Sigma Investments, and Citadel were also reportedly affected.nThe cybercriminals, operating under aliases like Redact, Pink, Falcon, and Helix, have recently shifted their focus to private equity firms, law firms, and financial ratings agencies. Google's Threat Intelligence Group indicated that these attackers appear to select targets based on their perceived ability and willingness to pay ransoms. While Google noted that the groups share infrastructure, their exact relationships and identities remain unclear. The attackers did not rely on sophisticated technical exploits.nInstead, the attackers utilized phone calls, impersonating corporate IT help desks to trick employees into divulging their credentials. Targets received calls on their personal mobile phones, often appearing to originate from their company’s genuine help desk, and were informed of an urgent need to update passkeys or multi-factor authentication credentials. Employees were then directed to fraudulent websites designed to mimic corporate authentication or support pages. If an employee entered their password, the attackers captured the one-time authentication code, gaining control of the account before ending the call.nAustin Larsen, a principal threat analyst at Google’s Threat Intelligence Group, noted that this approach, while not technically complex, proved effective. This campaign underscores the persistent human element as a critical vulnerability for private equity firms, which manage highly sensitive information related to portfolio companies, investment strategies, transactions, and financial data. Google identified 72 malicious websites linked to the campaign, with Reuters' analysis revealing many were customized for specific companies.nOver a five-week period, the attackers created digital traps targeting more than 200 businesses. Beyond financial services, the campaign also extended to companies such as Uber, Zillow, and Levi Strauss, as well as law firms including Paul Hastings and Greenberg Traurig. The campaign evolved over time, initially casting a wide net before narrowing its focus to financial institutions. Google reported that some companies paid ransoms following successful attacks, though specific identities and payment details were not disclosed. Several private equity firms mentioned in the report either declined to comment or did not respond to inquiries.nThis wave of social-engineering cyberattacks signals a growing threat to the private equity sector, emphasizing that even firms with robust cybersecurity infrastructure remain susceptible to attacks exploiting human vulnerabilities. The attackers' shift towards financial institutions indicates a calculated strategy to target entities with valuable data and a potential willingness to pay ransoms. This trend suggests an ongoing need for enhanced employee training in cybersecurity awareness and more resilient authentication protocols within the industry to mitigate these evolving threats.