Ransom hackers target US financial firms
Analysis based on 17 articles · First reported Aug 06, 2026 · Last updated Aug 06, 2026
The cyberattack campaign raises concerns about data security and potential financial losses for targeted firms, potentially impacting their reputations and stock prices. Ransom payments and remediation costs could affect earnings, while the incident highlights systemic cybersecurity risks in the financial sector.
Over the past month, a group of ransom-seeking hackers using phone-based social engineering targeted dozens of prominent U.S. financial institutions and other businesses. According to Alphabet Inc. and internet intelligence data reviewed by Reuters, the hackers created malicious websites designed to steal employee passwords from firms including Blackstone Inc., Bridgewater Associates, Apollo Global Management, Bain Capital, KKR & Co., TPG, CME Group, and Moody's, as well as hedge funds like Point72, Two Sigma, and Citadel. The hackers, operating under aliases such as Redaction, Pink, Falcon, and Helix, used low-tech tactics: they called employees on personal cellphones, impersonated company help desks, and directed them to fake passkey update sites to harvest credentials and multifactor authentication codes. Alphabet Inc. reported that some unnamed companies paid ransoms, though Reuters could not confirm which firms were successfully breached. The campaign also targeted law firms and other companies, including Uber, Zillow, Levi Strauss, Paul Hastings, and Greenberg Traurig. Experts note that despite advanced security, social engineering remains highly effective. The attacks have caused concern on Wall Street, with Point72 confirming it was targeted.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard