New Attack Vector Targets Trusted Identities in Financial Sector

Financial institutions are facing a sophisticated new cyber threat where attackers bypass technical security measures by exploiting human trust. Instead of attempting network breaches, these adversaries initiate campaigns through phone calls, impersonating help desk staff to gain access to corporate systems.

Recent Campaign Details

Google’s Threat Intelligence Group recently reported on UNC6671, a threat actor targeting major firms including Blackstone, Apollo Global Management, Bain Capital, Bridgewater Associates, KKR, TPG, CME Group, Clearlake Capital and Moody’s, as well as hedge funds like Point72, Citadel and Two Sigma. Over roughly five weeks, the attackers built digital traps for more than 200 companies.

Instead of brute-forcing security systems, UNC6671 members called financial services employees on their personal phones, posing as IT support handling urgent security migrations. Victims were directed to attacker-controlled login portals where adversary-in-the-middle technology captured credentials and authentication tokens.

The Attack Methodology

Attackers leverage a simple but effective technique: they convince employees to authenticate them rather than defeating authentication mechanisms.

  1. Initial Contact: Call financial professionals on personal devices, posing as IT staff
  2. Phishing via Voice: Direct victims to fake login pages that resemble legitimate corporate portals
  3. Credential Harvesting: Capture usernames, passwords, and MFA tokens through man-in-the-middle attacks
  4. Cloud Application Access: Once authenticated, move quickly into cloud environments to steal data and disable alerts
  5. Data Exfiltration: Automated scripts extract sensitive information from compromised accounts

Implications for Security Executives

The rise of this attack vector highlights a critical shift in cybersecurity: defenses must now address not just technical vulnerabilities but also human trust.

As financial institutions increasingly adopt cloud-based systems, attackers have more incentive to target legitimate identities rather than attempting network breaches. This means CISOs need to focus on:

  • Zero Trust principles: Verify every access request based on context and risk
  • Behavioral analytics: Detect anomalous activity even when users are authenticated
  • Help desk security: Implement stricter controls for password resets, MFA enrollments, and account changes
  • User awareness training: Educate employees about social engineering tactics

The financial sector has already increased fraud-detection budgets by 68% year-over-year in anticipation of more sophisticated attacks. As digital transformation continues, security investments must evolve to protect against this emerging threat landscape.