Major Financial Firms Breached in Vishing Campaign
Hackers are reportedly using simple phone calls to bypass security and steal data from prominent financial institutions, triggering SEC and state breach-notification duties.
A threat group is reportedly targeting dozens of major U.S. financial institutions, including Apollo, Blackstone, and KKR, using a low-tech "vishing" (voice phishing) method. Attackers call employees, impersonate IT staff, and direct them to spoofed login portals to capture credentials and multi-factor authentication (MFA) tokens, leading to data theft and ransom demands.
Sophisticated counsel and clients care because this social engineering approach bypasses many technical security controls, creating significant risk regardless of the company's security stack. A successful attack triggers a cascade of legal obligations, including state data breach notifications and reporting duties under the SEC's amended Regulation S-P and New York's NYDFS Part 500 cybersecurity rules. The regulatory scrutiny and litigation risk are identical to those from more technically complex intrusions.
Firms should immediately review and update security awareness training to address phone-based threats. Counsel should advise clients to harden help-desk verification protocols, accelerate adoption of phishing-resistant MFA, and pressure-test incident response plans against this specific scenario.