Hackers targeted US private equity, other firms including Blackstone, CME, data shows
Reuters, citing Google and internet intelligence data, reports ransom-seeking hackers used phone calls and tailored phishing sites to target employees at US financial firms. Targets included Blackstone, Bridgewater, Apollo, Bain Capital, KKR, TPG, CME Group and Moody’s. Google said some unnamed firms paid ransoms; Reuters could not confirm successful breaches.
How this was made

The 30-second read
Why it matters
The article increases perceived cyber tail-risk for named financial institutions by detailing how attackers harvest passcodes and hijack accounts, but it does not establish that any specific firm was successfully compromised.
Market read
This is a cyber-threat disclosure that can affect risk sentiment for targeted financials, but the lack of confirmed successful intrusions limits immediate tradable impact.
What to watch
Traders should watch for follow-on disclosures: whether any of the named firms confirm account takeovers, data exposure, customer impact, or regulator inquiries, which would materially change the risk assessment.
Background
Reuters, citing Google’s Threat Intelligence reporting, describes a phone-call-driven ransomware and credential-theft campaign using firm-specific malicious websites and social engineering.
Ticker impact
Reuters data reviewed by Google says hackers built password-stealing sites targeting employees at Blackstone.
Near-term impact likely limited without confirmation of successful compromise, but risk premium could tick up if incident details emerge.
The article names Blackstone as a target in the phishing campaign, yet Reuters could not establish successful compromises and no financial impact is quantified.
The campaign described by Google and Reuters included malicious subdomains aimed at compromising CME Group employees’ credentials.
Stock reaction likely muted unless follow-on reporting confirms compromise or material disruption.
CME is explicitly listed among targeted firms, but success is unverified and the article provides no outage, loss, or regulatory action.
Reuters reviewed data indicates the hackers created firm-specific traps aimed at stealing passwords from Apollo Global Management employees.
Likely low immediate price impact absent confirmation; watch for incident disclosures or remediation costs.
Apollo is named as a target and the attack method is detailed, but there is no evidence of successful compromise in the text.
The hacking campaign described by Google and Reuters included websites aimed at compromising KKR employees’ passkeys or MFA flows.
Near-term impact uncertain; could be limited unless follow-up confirms compromise or operational disruption.
KKR is explicitly named among targeted firms, but Reuters could not establish successful compromises and no quantified impact is provided.
Google’s Threat Intelligence blog, as summarized by Reuters, says the hackers targeted TPG employees with password-stealing websites.
Probably limited immediate market reaction without confirmation; risk premium may rise on further disclosures.
The text names TPG as a target and describes the passkeyhelpdesk lure, but provides no confirmation of success or losses.
Market effects
Reinforces that social-engineering and passkey/MFA harvesting remain effective, potentially increasing compliance and incident-response costs across financial services.
Primarily US financial institutions, with potential spillover to broader North American cyber-risk sentiment.
Could influence global cyber-insurance pricing and security spending narratives for multinational financial firms.
Counterpoint
Because Reuters could not confirm successful compromises, the market may treat this as a known threat pattern rather than a material, company-specific event.
Key entities
- private_equity_firmBlackstone
Named as one of the targeted firms whose employees were sent to password-stealing traps.
- financial_exchangeCME Group
Named as a targeted firm in the described credential-harvesting campaign.
- credit_ratings_agencyMoody’s
Named as a targeted firm; the article describes passkey/MFA harvesting mechanics.
- private_equity_firmApollo Global Management
Named as a targeted firm in the malicious website campaign.
- private_equity_firmKKR
Named as a targeted firm in the malicious website campaign.

