Technology
Google says hackers are calling financial firm employees to hack and extort victims
|3 min read
Hackers have been making phone calls to employees of large US financial firms, tricking them into giving away sensitive information that is then used to extort victims, Google's security researchers have found. This new tactic is a departure from the usual phishing emails and instead relies on social engineering to gain access to company systems. The researchers identified 15 groups of hackers using this method, with some groups making over 100 calls per day. The hackers are targeting firms with high-value assets, such as investment banks and private equity firms, and are using the stolen data to demand ransom payments.
What to expect from hackers
The use of phone calls to trick employees into giving away sensitive information is a new twist on the usual phishing scams. This tactic is particularly effective because it is more personal and can be more convincing than a phishing email. The hackers are using a combination of research and social engineering to make the calls more convincing, often using information found on social media or company websites to make the calls seem more legitimate.
Background on hacking groups
The 15 groups of hackers identified by Google's researchers are all using similar tactics, but some are more sophisticated than others. Some groups are using automated systems to make the calls, while others are using human operators. The groups are also using different types of scams, including pretending to be IT support or claiming to be from a government agency. The researchers found that the hackers are often demanding ransom payments in cryptocurrency, such as bitcoin, and are using the stolen data to extort victims.
Next steps for financial firms
The fact that hackers are now using phone calls to trick employees into giving away sensitive information is a wake-up call for financial firms to review their security protocols. Financial firms need to educate their employees on how to spot these types of scams and how to report them. The firms also need to implement more robust security measures, such as two-factor authentication and encryption, to protect their systems and data. The use of phone calls by hackers is a reminder that security is an ongoing process and that firms need to stay vigilant to protect themselves from these types of attacks.
Financial firms are vulnerable to these types of attacks because they often have high-value assets and sensitive information that can be used to extort victims. The use of phone calls by hackers is a new twist on the usual phishing scams and highlights the need for financial firms to stay ahead of the hackers. The fact that the hackers are demanding ransom payments in cryptocurrency is also a concern, as it makes it difficult to track the payments and bring the hackers to justice.
The conclusion is that financial firms need to take immediate action to protect themselves from these types of attacks. The use of phone calls by hackers is a reminder that security is an ongoing process and that firms need to stay vigilant to protect themselves from these types of attacks. With the right security measures in place, financial firms can reduce the risk of these types of attacks and protect their systems and data, the key takeaway is that education and awareness are crucial in preventing these types of attacks, Google's researchers found that 75% of the attacks could have been prevented if the employees had been educated on how to spot these types of scams.
Related Articles
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
A shocking discovery has been made in the world of cybersecurity, as researchers have uncovered a Ch...
Ford needs another Taurus, and the $30K Fathom EV pickup isnโt it
Ford's CEO has just made a startling claim that the new Ford Fathom is a game-changer for the compan...
Hacker pleads guilty to stealing data from more than 165 Snowflake customers
A staggering 165 Snowflake customers had their data stolen by a single hacker, Connor Moucka, who ha...