CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

Google says hackers are calling financial firm employees to hack and extort victims

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4023

As cited

Copy frozen at (site build).

threat intel

Google says hackers are calling financial firm employees to hack and extort victims

Google's security researchers documented a campaign where threat actors gain initial access to large U.S. financial firms by calling employees, then stealing sensitive data and extorting victims. The tactic demonstrates how social engineering via phone calls remains an effective vector for breaching enterprise targets in the financial sector.

Why it matters: Financial services firms and their employees face direct risk from phone-based social engineering targeting account access; security teams should review call screening, employee training, and incident response procedures for initial compromise via this vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Google says hackers are calling financial firm employees to hack and extort victims

Google's security researchers documented a campaign where threat actors gain initial access to large U.S. financial firms by calling employees, then stealing sensitive data and extorting victims. The tactic demonstrates how social engineering via phone calls remains an effective vector for breaching enterprise targets in the financial sector.

Why it matters: Financial services firms and their employees face direct risk from phone-based social engineering targeting account access; security teams should review call screening, employee training, and incident response procedures for initial compromise via this vector.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary