9 Major PE & Financial Firms Targeted by Voice Phishing in 4-Group Campaign
A coordinated vishing campaign by groups Redact, Pink, Falcon, and Helix targeted Blackstone, CME, and seven other financial giants, using fake login sites and phone calls. Google confirmed some victims paid ransoms. The attack underscores how even top-tier security can be bypassed by exploiting human trust.
Key Takeaways
- A coordinated vishing campaign by groups Redact, Pink, Falcon, and Helix targeted Blackstone, CME, and seven other financial giants, using fake login sites and phone calls.
- Google confirmed some victims paid ransoms.
- The attack underscores how even top-tier security can be bypassed by exploiting human trust.
Mentioned
Key Intelligence
Key Facts
- 1Hackers created phishing websites to steal employee credentials from at least 9 major private equity and financial firms, including Blackstone, CME Group, Bridgewater, Apollo, KKR, and Moody’s.
- 2The threat actors, tracked as Redact, Pink, Falcon, and Helix, used phone calls (vishing) to convince employees to visit the fake login pages.
- 3Google’s Threat Analysis Group confirmed that some victim organizations paid ransoms, though Reuters could not verify which.
- 4The campaign targeted dozens of firms overall, with a focus on private equity, law firms, and financial services.
- 5Industry experts note that low-tech social engineering remains highly effective, exploiting human trust even in environments with advanced cybersecurity defenses.
Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us.
Commenting on the effectiveness of phone-based social engineering in the latest campaign
Analysis
For cybersecurity professionals, the latest campaign against the private equity sector is a textbook case of why social engineering remains the most reliable attack vector. With multi-million-dollar defenses in place at firms like Blackstone and CME, the attackers didn't need zero-days—they just picked up the phone. This incident provides fresh evidence that vishing, when combined with credential-harvesting phishing sites, can penetrate even the most fortified financial institutions.
An active cyber-espionage and extortion campaign has been targeting prominent U.S. private equity firms and financial institutions, leveraging low-tech phone-based social engineering to bypass sophisticated security perimeters. Data reviewed by Reuters and a Google blog post published on August 6, 2026, reveal that threat actors—operating under the aliases Redact, Pink, Falcon, and Helix—constructed phishing websites aimed at harvesting credentials from employees of at least nine major firms, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s. The hackers used voice phishing (vishing) calls to persuade targets to visit these fake login portals, a technique that exploits human psychology rather than technical vulnerabilities.
Blackstone (BX) and CME Group (CME) shares showed mixed reactions in early trading following the report, with BX dipping 0.8% and CME edging up 0.3%.
The campaign unfolded over the past month, with Google’s Threat Analysis Group noting that the groups recently shifted focus to private equity, law firms, and financial services, sectors where a successful breach could yield sensitive deal-flow data, market-moving intelligence, and personal client information. Some victim organizations paid ransoms, according to Google, though the specific companies and amounts remain undisclosed. Reuters’ own investigation, however, could not independently confirm which entities were successfully compromised. The hackers’ reliance on phone calls underscores a persistent challenge: while organizations invest heavily in AI-driven threat detection, endpoint security, and zero-trust architectures, the human element consistently remains the weakest link. As Lee Clark of the Retail and Hospitality ISAC observed, “Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us.”
The targeting of private equity titans carries profound implications. Blackstone, KKR, and Apollo collectively manage trillions in assets and hold privileged information about portfolio companies, M&A activity, and investor commitments. A breach at any of these firms could lead to the exfiltration of material non-public information, potentially triggering market manipulation, insider trading, or reputational crises. Moreover, ransom payments to the groups may incentivize further attacks, creating a pernicious cycle that endangers the broader financial ecosystem. Regulatory bodies, including the SEC and FTC, will likely scrutinize the incident, particularly given new cybersecurity disclosure rules that require publicly listed companies to report material breaches. The fact that some firms paid ransoms may also attract attention from the U.S. Treasury’s Office of Foreign Assets Control (OFAC), which has warned that ransom payments could violate sanctions if the recipients are sanctioned entities.
From a market perspective, the news coincides with growing investor anxiety around cybersecurity risks in the financial sector. Blackstone (BX) and CME Group (CME) shares showed mixed reactions in early trading following the report, with BX dipping 0.8% and CME edging up 0.3%. While the immediate financial impact appears limited, prolonged uncertainty or disclosure of a material breach could weigh on valuations, especially for firms that rely heavily on trust and confidentiality.
What to Watch
Looking ahead, the campaign signals a shift in attacker tactics. The groups’ agility in pivoting from traditional ransomware targets to high-value financial services reflects an evolving threat landscape where human-operated social engineering remains formidable. Mitigation will require not just technical controls but also enhanced security awareness training, stronger verification protocols for unusual requests, and possibly regulatory mandates for multi-factor authentication and call-back procedures. For investors, the incident highlights the importance of evaluating portfolio companies’ cyber resilience as a key ESG and operational risk factor.
In sum, the Redact/Pink/Falcon/Helix campaign is a stark reminder that in cybersecurity, humans are both the greatest asset and the greatest vulnerability. As private equity and financial markets become ever more digitized, the ability to defend against socially engineered intrusions will be a critical determinant of long-term resilience.
Timeline
Timeline
Phishing Campaign Launched
Hackers begin creating fake login websites and making vishing calls targeting employees at major private equity and financial firms.
Google Publishes Threat Intel Blog
Google's Threat Analysis Group reveals that groups Redact, Pink, Falcon, and Helix are behind the campaign targeting private equity, law, and financial sectors, noting some victims paid ransoms.
Reuters Publishes Exclusive Investigation
Reuters reports on the targeted firms based on Google and internet intelligence data, identifying Blackstone, CME, Bridgewater, Apollo, and others.
Sources
Sources
Based on 2 source articles- bworldonline.comHackers targeted US private equity , other firms including Blackstone , CME , data showsAug 7, 2026
- finance.yahoo.comExclusive - Hackers targeted US private equity , other firms including Blackstone , CME , data showsAug 6, 2026
Cite This Page
"9 Major PE & Financial Firms Targeted by Voice Phishing in 4-Group Campaign." Cyber Intelligence Brief, August 7, 2026. https://getcyberbrief.com/story/9-pe-financial-firms-voice-phishing-redact-pink-falcon-helix
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |