Ransom-seeking hackers employing phone calls to compromise their targets have set their sights on dozens of prominent U.S. financial institutions and other businesses over the past month, according to findings from Google and internet intelligence data reviewed by Reuters.

The cybercriminals reportedly crafted sophisticated websites designed to steal passwords from employees at major private equity firms and financial companies, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's, among others.

Google, in a blog post published Thursday, revealed that the hackers operate under various aliases such as Redact, Pink, Falcon, and Helix. While Google declined to comment on Reuters' specific findings, its blog indicated that some unnamed companies had paid ransoms to the hackers.

However, Reuters could not independently confirm which firms were successfully compromised.

Experts highlight that the hackers' reliance on low-tech tactics, particularly phone calls, to infiltrate the financial sector underscores a critical vulnerability. Despite the prevalence of advanced security programs and AI-driven threats, these older, more direct methods remain remarkably effective.

Successful breaches could expose sensitive data from some of the largest U.S. private equity firms that provide capital to numerous companies.

Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, an industry information sharing and analysis group, explained the simplicity behind the strategy.

"Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us," he stated. Clark added, "That human element consistently is why this has exploded in the way it has."

Several targeted firms, including KKR, Bain Capital, Clearlake Capital, CME, TPG, and Apollo, declined to comment on the attacks. Blackstone, Bridgewater Associates, and Moody's did not immediately respond to requests for comment.

Google, a unit of Alphabet, noted in its blog post that the hackers have recently shifted their focus to private equity firms, law firms, and financial ratings agencies.

Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, explained that the hackers typically target industries based on financial calculations, often with success. "Really, it’s a money thing," Larsen said. "They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it."

While Google did not name specific targets, Reuters independently identified many of the company-specific online traps. This was achieved by analyzing the 72 malicious websites listed in Google's report through web intelligence platforms like DomainTools and urlscan, which flagged malicious subdomains tailored to individual firms.

Larsen confirmed that "They all were likely used in attempted intrusions," though he cautioned, "They were not all successful."

The hackers employed "meticulous social engineering tactics," contacting employees on their personal cellphones while impersonating their company’s help desk, sometimes even spoofing the correct help desk phone number.

They would then inform targets of an urgent IT directive to update passkeys or multifactor authentication, directing them to deceptive websites with domain names such as "passkeyhelpdesk" or "secure-passkey."

If an employee entered their password, the hackers would harvest their fail-safe passcode – typically sent via text or generated by an app – live over the phone, hijacking their account before the call ended. Larsen emphasized that this tactic, while effective, is not particularly advanced.

"Sophisticated is not the right word," he said. "It is just really effective."

Reuters was unable to reach the alleged hackers. Redact, which previously operated as Blackfile, stated on its darknet website that its hackers "are not politically or morally motivated" and were "not currently taking questions from the press."

Falcon, another group, acknowledged affiliation with Redact but denied any connection to Helix or Pink. Larsen noted that the exact identities of the hackers and their relationships remain unclear, despite their apparent use of common infrastructure. "There are still some unknowns here," he said.

These hacking attempts, some of which were previously reported by Bloomberg, have caused concern on Wall Street. Point72 Asset Management, for instance, informed investors Wednesday that it had been targeted, according to a source familiar with the matter.

This source, along with another, indicated that other hedge funds, including Two Sigma Investments and Citadel, whose names also appeared in Reuters' data, were targeted as well. Two Sigma did not return requests for comment, while Citadel and Point72 declined to comment.

Before focusing on financial institutions, the hackers had other firms in their crosshairs, as detailed in Google's blog post and the reviewed data.

Over the past five weeks alone, the cybercriminals constructed digital traps for more than 200 companies, including ride-hailing giant Uber, online broker Zillow, and jeans brand Levi Strauss, as well as several law firms such as Paul Hastings and Greenberg Traurig.

Uber, Zillow, Paul Hastings, and Levi Strauss did not return messages seeking comment. Greenberg Traurig issued a statement asserting it "did not have a data breach given the layers of security protocols we have in place to protect client data and the firm," without providing further details.