August 9, 2026 — A new crisis is unfolding in the world of cybersecurity. According to data provided by Google and confirmed by Reuters, dozens of leading American financial institutions, investment funds, and law firms have fallen victim to coordinated attacks by hacker groups over the past month. The perpetrators, operating under the pseudonyms Redact, Pink, Falcon, and Helix, have demonstrated unprecedented effectiveness by combining cutting-edge artificial intelligence technologies with primitive yet effective social engineering methods.
Scale of the Attack: From Blackstone to Moody's
The targets of the attackers were organizations with access to confidential data and large financial flows. The list of victims includes giants such as Blackstone, Bridgewater Associates, Apollo, KKR, TPG, CME Group, Clearlake Capital, and the rating agency Moody's. Hackers created a network of 72 fake websites that accurately mimicked legitimate corporate resources. The goal of these resources was to steal employee credentials, which would allow criminals to access internal networks and client data.
The Technology Paradox: Why Calls Are More Effective Than Viruses
Despite using complex hacking software created with the help of artificial intelligence, hackers delivered the main blow through phone calls. Lee Clark, a Threat Intelligence Production Manager at Retail and Hospitality ISAC, explains this phenomenon with a simple metaphor: "Since fences are now modern and high-tech, we just need to trick the guard into opening the door for us".
Analysts note that the human factor remains the weakest link in the security chain. Hackers contacted employees on their personal mobile phones, posing as technical support. Using Caller ID spoofing technology, they displayed real company numbers on employees' phone screens, which generated trust.
Hacking Mechanics: Stealing Passwords and Backup Codes
The attack scenario was automated to perfection. Perpetrators reported an "urgent instruction from the IT department" to update passwords or set up multi-factor authentication. Employees were directed to trap sites with domain names such as passkeyhelpdesk or secure-passkey. If an employee entered their data, hackers instantly requested a backup access code (usually sent via SMS or generated by an app). Upon receiving the code, criminals hacked the account before the phone call even ended.
Shift in Vector: Why Private Funds Are in the Crosshairs
Recently, there has been a clear shift in cybercriminal tactics. While retail and the government sector were previously the main targets, hackers have now switched to private investment funds, law firms, and rating agencies. Austin Larsen, a senior analyst at Google Threat Intelligence Group, notes: "They believe these firms hold confidential data, and in the event of a theft, they would pay to prevent it".
Contradictory Data
While Google and Reuters have provided a detailed picture of the attacks, there are discrepancies in the details between various sources. While Google focuses on social engineering methods and credential theft, some independent industry analysts suggest that the attacks may be orchestrated not just by a ransomware group, but by a more complex structure aimed at industrial espionage. Furthermore, the exact number of affected companies varies across reports: while Google cites "dozens," some sources indicate that the real scale may be broader, as many companies hide such incidents to avoid panicking the markets.