Google’s security researchers have identified a new wave of targeted attacks against large U.S. financial institutions, using a combination of phone calls and data theft to extort victims.
The attackers reportedly call employees, often impersonating executives or support staff, to gain access to internal systems.
Once inside, the attackers harvest sensitive data, including customer account details and proprietary trading algorithms.
The stolen information is then used to threaten employees or the firms themselves, demanding ransom or threatening public disclosure.
The researchers say the attacks are sophisticated, with attackers leveraging known vulnerabilities in outdated software and exploiting weak authentication practices.
The financial firms have reported that these incidents have caused significant operational disruptions and financial losses.
Google recommends that firms strengthen multi‑factor authentication, conduct regular security audits, and train staff to recognize social‑engineering tactics.
The researchers also urge the industry to share threat intelligence and coordinate incident response to mitigate the spread of such attacks.
We see a clear pattern of attackers combining phone-based social engineering with cyber intrusion to extort victims, said a Google security researcher.
The study highlights the need for firms to adopt a zero‑trust security model and to monitor for unusual outbound traffic that could indicate data exfiltration.