Private equity firms have become the latest targets of hackers using vishing to steal employee credentials. The group UNC6671, tracked by Google Threat Intelligence Group, impersonates IT support staff and redirects victims to fake login portals. These hackers intercept credentials and multi-factor authentication tokens before extracting data from Microsoft 365 and Okta. Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s were among the targets. According to Google, some firms paid the ransom.
Source: Read the original article

