Phone Hackers Target Wall Street Giants Blackstone and CME in Big Password Scam

Hackers use fake help-desk calls and trick websites to target Wall Street giants like Blackstone and CME Group in a massive password theft campaign.
Image Credit / Reuters

Hackers use fake phone calls and fake websites to steal passwords from staff at Wall Street giants like Blackstone and CME.

Dangerous cybercriminals have launched a heavy hacking campaign targeting big American financial corporations, including private equity powerhouse Blackstone and major exchange operator CME Group. Reports released by Google’s Threat Intelligence Group on Thursday, August 6, 2026, show that ransom-seeking hackers spent recent weeks executing clever social engineering attacks across Wall Street. Instead of using super-complex code to break through tough corporate firewalls, the intruders simply used telephone calls to trick workers into giving away their login credentials.

The wide-reaching cyber operation unfolded across major U.S. financial hubs, taking direct aim at multi-billion-dollar investment companies, private equity firms, and credit rating agencies. Cybersecurity analysts revealed that the hackers targeted employees working at top-tier firms like Bain Capital, Apollo Global Management, KKR, TPG, Moody’s, and Bridgewater Associates. Operating under darknet aliases like Redact, Pink, Falcon, and Helix, the extortionists carefully registered over seventy fake domain names designed to mimic official internal software pages for each specific company.

To understand how these hackers managed to breach high-security financial firms without advanced military-grade malware, look at how simple human trickery can beat expensive computer security. The attackers called staff members on their personal mobile phones while spoofing the exact telephone number of their company’s IT help desk. Pretending to be friendly internal IT support staff, the callers warned the workers that an urgent security directive required them to update their passkeys immediately. They then guided the victims to fake web pages carrying names like “passkeyhelpdesk” or “secure-passkey”. As soon as an employee entered their password, the hackers captured the one-time security code over the phone in real time and hijacked the corporate account.

See Also: South Korean “Ant” Investors Rush Back to Wall Street as KOSPI Market Crashes

This attack wave highlights why private equity firms and hedge funds have suddenly become top targets for international cyber extortionists. Security experts explain that investment firms handle secret deal documents, live merger negotiations, and high-value corporate files. Hackers know that if they successfully steal sensitive deal data, victim companies face huge pressure to quietly pay multi-million-dollar ransoms rather than let confidential client business leak to the public.

While several targeted companies responded quickly to block the intrusion attempts, threat analysts confirmed that some unnamed businesses suffered account compromises and paid ransoms to clear the threats. The Financial Industry Regulatory Authority and Google have issued fresh security guidelines urging companies to enforce physical hardware security keys and implement strict verification steps before handling help-desk phone requests. As financial institutions continue upgrading their digital defenses, this massive phone scam serves as a loud warning that the simplest social engineering tactics remain surprisingly effective against major corporations.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst and writer covering artificial intelligence, fintech, and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.