Some of the world’s biggest financial firms are being targeted by a surprisingly old-school cyberattack: phone calls.
A widespread “vishing” campaign (voice phishing) has targeted large finance companies including Blackstone, KKR and CME Group, with attackers posing as corporate IT or help desk employees. Their goal is to convince workers to provide login credentials, authentication information or other details that can be used to access company systems.
The attacks demonstrate why social engineering remains such a difficult cybersecurity problem. Even sophisticated security technology can be undermined when criminals successfully impersonate trusted employees.
For companies and workers, the takeaway is simple: unexpected requests for passwords, authentication codes or account changes should always be independently verified through established internal channels.

/Passle/60211dc9e5416a0c14bc63d4/SearchServiceImages/2026-07-31-14-46-50-064-6a6cb55a76361c6942060d6e.jpg)
/Passle/60211dc9e5416a0c14bc63d4/SearchServiceImages/2026-08-05-13-31-04-436-6a733b18cc06f5a64abda229.jpg)
/Passle/60211dc9e5416a0c14bc63d4/SearchServiceImages/2026-08-05-02-23-43-575-6a729eaf17298b6fcc4e91f7.jpg)




