Hackers Dial for Dollars: Blackstone, KKR Among Dozens of Wall Street Firms Targeted in Vishing Blitz — BigGo Finance
Google’s Threat Intelligence Group and Reuters report a five-week vishing campaign targeting employees at dozens of financial firms, including Blackstone, KKR, Apollo Global Management, and others. Attackers posed as IT help desks, used spoofed numbers and fake login pages to steal passwords and MFA codes. Demands reportedly ranged from $750,000 to $3 million, with some ransoms reportedly paid.
How this was made
The 30-second read
Why it matters
The article increases perceived cyber and operational risk for named financial and tech firms, but it does not confirm which organizations were actually compromised or quantify losses.
Market read
This is a cybersecurity threat report that can move sentiment for named firms, but it provides no verified breach outcomes or financial disclosures.
What to watch
Traders may overreact to the extortion framing; the article lacks verified compromise details, and firms declined comment, suggesting uncertainty about materiality.
Background
Google Threat Intelligence Group and Reuters analysis describe a five-week vishing campaign using spoofed help desk calls and firm-specific fake login sites to harvest passwords and MFA codes.
Ticker impact
Blackstone is named as a target in a vishing campaign that harvested passwords and MFA codes via fake login pages.
Near-term sentiment risk only; no clear catalyst for a directional move from this article alone.
The piece describes targeting and tactics, but Reuters says it could not independently verify specific compromises, and no incident outcome or financial disclosure is included.
KKR is listed among dozens of private equity firms targeted by phone-based vishing to steal credentials and MFA codes.
Limited price impact expected unless follow-on reporting confirms a breach or material data theft.
The article provides scope and method, but does not identify confirmed victimization for KKR or any resulting costs.
Apollo Global Management is included among firms targeted in the vishing blitz aimed at harvesting passwords and MFA codes.
Low conviction directional move; watch for later confirmation of breach and any incident-related disclosures.
The report is about targeting and extortion motives; it explicitly notes inability to independently verify which companies were compromised.
CME Group is named as one of the organizations targeted, with attackers using spoofed help desk calls and fake login portals.
Potential volatility only if subsequent reporting confirms service disruption or data loss.
The article describes tactics and extortion demands, but provides no confirmed breach details for CME.
Uber is mentioned among consumer-facing tech companies targeted via vishing calls that direct employees to credential-harvesting sites.
No clear trade signal without follow-on confirmation of an actual incident.
The article focuses on the campaign mechanics and motives; it does not establish that Uber employees were successfully compromised.
Zillow is included in the list of organizations targeted in the vishing blitz using fake login pages to harvest passwords and MFA codes.
Directional impact unlikely from this report alone; monitor for later disclosures.
Reuters could not independently verify which specific companies were successfully compromised, reducing immediate trading relevance.
Market effects
Highlights persistent human-factor vulnerability in financial services, potentially increasing compliance and security spending focus across the sector.
Primarily US-focused targets, but could raise broader North American cyber-risk premium for financials.
Google and Reuters reporting may influence global cyber threat monitoring and incident-response expectations for multinational firms.
Counterpoint
Being named as a target does not mean a successful breach occurred; confirmed incidents and costs are not provided, so price impact may be overstated.
Key entities
- sourceGoogle Threat Intelligence Group
Identified the vishing methodology and tracked related hacking groups under multiple monikers.
- threat_actorUNC6671
Google’s collective tracking label for the broader phishing-as-a-service activity.
- companyBlackstone
Named target in the vishing campaign.
- companyKKR
Named target in the vishing campaign.
- companyApollo Global Management
Named target in the vishing campaign.




