Skip to main content
← Back to market wire
FundingTechCrunch

Google says hackers are calling financial firm employees to hack and extort victims

Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.

Desk analysis

AI-assisted2 min read

Google's threat intelligence unit has identified a coordinated campaign in which hackers are bypassing technical defenses and going straight for the human layer. The targets are employees at large U.S. financial firms, and the method is vishing: voice calls engineered to extract credentials or push victims toward malware-laden sites.

The tactic is not new, but the scale and the follow-through are worth noting. These are not opportunistic scammers fishing for a quick wire transfer. According to Google's researchers, the intrusions are designed to steal sensitive data and then extort the victims. That implies a structured operation with clear incentives, likely tied to the sensitive client information and proprietary deal flow that sits inside private equity and venture capital firms.

Financial institutions have spent heavily on perimeter defenses, endpoint detection, and multi-factor authentication. Attackers respond by targeting the one variable that cannot be patched: the employee who answers an unexpected call. A well-rehearsed caller posing as IT support or a vendor can often obtain the same access that a zero-day exploit would provide, at a fraction of the cost.

The extortion element changes the calculus for the victims. A breach that exposes personal financial data is no longer just a compliance headache; it becomes a direct threat to individuals. That pressure can push firms toward quiet settlements rather than public disclosure, which in turn funds the next round of attacks.

For the broader market, this is a signal about where cyber risk is concentrating. The most valuable data is no longer locked in corporate servers alone. It lives in the inboxes, call logs, and remote access sessions of employees who are one convincing phone call away from compromise. Firms that treat vishing as a training footnote rather than a primary threat vector are misreading the current landscape.

Google's report is a reminder that the human element remains the softest target in any security architecture. The technology will keep improving, but so will the scripts on the other end of the line.