NewsMacroHackers Target Blackstone, Apollo, and KKR Employees in Credential Theft Campaign

Hackers Target Blackstone, Apollo, and KKR Employees in Credential Theft Campaign

Author: CryptoMeter io·

Key Takeaways

  • Attackers impersonated internal IT help desk personnel and used spoofed company phone numbers to trick employees at private equity and financial firms into surrendering login credentials.
  • Google reported that the threat actors built customized phishing websites for over 200 organizations within a five-week period.
  • Targeted firms included Blackstone, Apollo Global Management, KKR, Bain Capital, TPG, CME Group, Moody's, Clearlake Capital, and Bridgewater Associates.
  • The campaign used a hybrid vishing approach that combined deceptive phone calls with realistic phishing portals to bypass multifactor authentication.
  • It remains unclear which specific companies were successfully compromised, although some organizations reportedly paid ransoms.
Hackers Target Blackstone, Apollo, and KKR Employees in Credential Theft Campaign

A sophisticated cybercrime campaign has targeted employees at several major U.S. private equity firms, including Blackstone, Apollo Global Management, and KKR, using deceptive phone calls designed to steal employee credentials and bypass multifactor authentication.

According to Google, the attackers relied on social engineering rather than advanced malware. They impersonated internal IT help desk staff, frequently calling employees on their personal mobile phones while spoofing legitimate company phone numbers. The callers claimed there was an urgent need to update security settings, passkeys, or multifactor authentication.

How the Attack Worked

The campaign combined convincing phone calls with company-specific phishing websites that closely mimicked legitimate IT support portals. Victims were instructed to log in or enter one-time authentication codes, enabling the attackers to capture passwords and session credentials in real time. This approach — sometimes called hybrid vishing — reflects a broader shift in which attackers, facing widespread adoption of multifactor authentication, increasingly target the human layer rather than attempting to defeat technical controls outright.

Google reported that the hackers built customized phishing infrastructure for more than 200 organizations over a five-week period. In addition to Blackstone, Apollo, and KKR, other identified targets included Bain Capital, TPG, CME Group, Moody's, Clearlake Capital, Bridgewater Associates, and several law firms and corporations.

Growing Focus on Financial Firms

Cybersecurity researchers believe the attackers have increasingly directed their efforts toward private equity firms, financial institutions, and professional services companies, drawn by the highly sensitive financial information and privileged access these organizations possess. Private equity firms in particular handle confidential deal data, limited partner information, and portfolio company strategy — material that could be valuable for insider trading, extortion, or competitive intelligence if stolen.

Google identified the threat actors under several aliases, including Redact, Pink, Falcon, and Helix. While some organizations reportedly paid ransoms, it remains unclear which companies, if any, were successfully compromised. The targeted firms have largely declined to comment publicly.

The campaign underscores that human-focused attacks remain among the most effective techniques available to cybercriminals. Rather than exploiting software vulnerabilities, the attackers manipulated employees into voluntarily surrendering credentials — highlighting the importance of verifying unexpected IT requests through official internal channels and never sharing passwords or authentication codes over the phone.