---
title: "Cyberattack on the US Financial Sector: How Hackers Bypass Security Using Calls and AI"
description: "🚨 <strong>Cyberattack on the US Financial Sector</strong> Hacker groups (Redact, Pink, Falcon, Helix) have attacked dozens of major financial companies, including Blackstone and Moody's. 🔑 <strong>Attack Method:</strong> Hackers created 72 phishing sites and use calls posing as tech support. They force employees to update passwords and dictate codes from SMS messages. 📉 <strong>Goal:</strong> Theft of confidential data from private investment funds and law firms. 🧠 <strong>Conclusion:</strong> The human factor remains the main vulnerability, despite the implementation of AI in security."
date: 2026-08-09T13:40:17.000Z
lang: en
url: https://xab.info/en/posts/cyberattack-on-us-financial-sector-2026
tags: [cybersecurity, hacking, finance, us-economy, social-engineering, data-breach]
publisher: "XAB.info"
---

# Cyberattack on the US Financial Sector: How Hackers Bypass Security Using Calls and AI

![Glasses in front of a screen showing code and cybersecurity interface — symbolizing hacker attack on US financial sector using AI and calls](https://xab.info/media/2026/08/09/hakers-atakovali-finansovye-kompanii-ssha-2026/hakers-atakovali-finansovye-kompanii-ssha-2026-1.webp)

## 🎯 Key Points

- Dozens of US financial companies have become victims of attacks by hacker groups Redact, Pink, Falcon, and Helix.
- Perpetrators use a combination of AI and social engineering (calls from tech support).
- 72 phishing sites were created to steal passwords and backup access codes.
- The main targets were private investment funds and law firms.

**August 9, 2026** — A new crisis is unfolding in the world of cybersecurity. According to data provided by Google and confirmed by Reuters, dozens of leading American financial institutions, investment funds, and law firms have fallen victim to coordinated attacks by hacker groups over the past month. The perpetrators, operating under the pseudonyms Redact, Pink, Falcon, and Helix, have demonstrated unprecedented effectiveness by combining cutting-edge artificial intelligence technologies with primitive yet effective social engineering methods.

### Scale of the Attack: From Blackstone to Moody's

The targets of the attackers were organizations with access to confidential data and large financial flows. The list of victims includes giants such as **Blackstone, Bridgewater Associates, Apollo, KKR, TPG, CME Group, Clearlake Capital, and the rating agency Moody's**. Hackers created a network of 72 fake websites that accurately mimicked legitimate corporate resources. The goal of these resources was to steal employee credentials, which would allow criminals to access internal networks and client data.

### The Technology Paradox: Why Calls Are More Effective Than Viruses

Despite using complex hacking software created with the help of artificial intelligence, hackers delivered the main blow through phone calls. Lee Clark, a Threat Intelligence Production Manager at Retail and Hospitality ISAC, explains this phenomenon with a simple metaphor: "Since fences are now modern and high-tech, we just need to trick the guard into opening the door for us".

Analysts note that the human factor remains the weakest link in the security chain. Hackers contacted employees on their personal mobile phones, posing as technical support. Using Caller ID spoofing technology, they displayed real company numbers on employees' phone screens, which generated trust.

### Hacking Mechanics: Stealing Passwords and Backup Codes

The attack scenario was automated to perfection. Perpetrators reported an "urgent instruction from the IT department" to update passwords or set up multi-factor authentication. Employees were directed to trap sites with domain names such as *passkeyhelpdesk* or *secure-passkey*. If an employee entered their data, hackers instantly requested a backup access code (usually sent via SMS or generated by an app). Upon receiving the code, criminals hacked the account before the phone call even ended.

### Shift in Vector: Why Private Funds Are in the Crosshairs

Recently, there has been a clear shift in cybercriminal tactics. While retail and the government sector were previously the main targets, hackers have now switched to private investment funds, law firms, and rating agencies. Austin Larsen, a senior analyst at Google Threat Intelligence Group, notes: "They believe these firms hold confidential data, and in the event of a theft, they would pay to prevent it".

### Contradictory Data

While Google and Reuters have provided a detailed picture of the attacks, there are discrepancies in the details between various sources. While Google focuses on social engineering methods and credential theft, some independent industry analysts suggest that the attacks may be orchestrated not just by a ransomware group, but by a more complex structure aimed at industrial espionage. Furthermore, the exact number of affected companies varies across reports: while Google cites "dozens," some sources indicate that the real scale may be broader, as many companies hide such incidents to avoid panicking the markets.

## 🔍 Fact-Check Verification

- [Ransomware Hackers Attack Major US Financial Companies](https://www.gazeta.ru/tech/news/2026/08/07/29056375.shtml) - Подтверждает масштаб атак и список пострадавших компаний.
- [Reuters: Hackers Attack Dozens of Major US Financial Companies](https://www.kommersant.ru/doc/8864343) - Подтверждает информацию о методах атак и цитатах экспертов Google.

## ❓ FAQ

### Q: Which companies were affected by the attacks?
**A:** The list of victims includes Blackstone, Bridgewater Associates, Apollo, KKR, TPG, CME Group, Clearlake Capital, and Moody's.

### Q: How do hackers bypass security?
**A:** They call employees, posing as tech support, and force them to enter passwords on fake websites.

### Q: Who is behind the attacks?
**A:** Google has identified groups under the names Redact, Pink, Falcon, and Helix.