Wird geladen…
  • August 7, 2026
  • Von aOneITForce

Helpdesk Calls Become the Front Door in Attacks on Wall Street Firms

Helpdesk Calls Become the Front Door in Attacks on Wall Street Firms

<p><strong>News Date: 2026-08-06</strong></p><p>A campaign targeting some of the financial sector's most valuable organizations shows that a convincing telephone call can still defeat an expensive security stack. The activity, tracked by Google Threat Intelligence Group as UNC6671, has reportedly targeted hedge funds, private-equity firms, law firms and financial-rating agencies using voice phishing and cloud-focused extortion.</p><h2>From Helpdesk Impersonation to Cloud Access</h2><p>The attackers call employees on personal mobile phones while posing as members of the corporate helpdesk. They typically claim that the employee must update multifactor authentication settings or enroll a passkey. The victim is then directed to a counterfeit corporate website equipped with an adversary-in-the-middle phishing system.</p><p>This approach can capture credentials and active session cookies in real time. Once an attacker controls a Microsoft 365 or Okta single sign-on account, the initial compromise may provide access to numerous connected cloud applications. Automated tools can then collect data at scale, while the attackers may delete password-reset messages and security notifications to delay discovery.</p><p>Google reportedly connects the intrusion team to the operation previously branded as BlackFile. The group is believed to use several public extortion identities, although one of the named brands has disputed parts of that assessment. Mandiant is assisting several dozen affected organizations, indicating that the campaign extends beyond a handful of attempted intrusions.</p><h2>Why Financial Firms Are Attractive</h2><p>Investment businesses hold market-sensitive documents, investor information, legal records and communications involving major transactions. Even without encrypting systems, criminals can threaten considerable reputational and regulatory damage by stealing this material.</p><h3>Defensive Priorities</h3><ul><li>Require independent verification for unsolicited helpdesk calls.</li><li>Restrict authentication changes to managed workflows and approved devices.</li><li>Monitor new session creation, mailbox rule changes and unusual cloud downloads.</li><li>Use phishing-resistant authentication while recognizing that session theft remains possible.</li><li>Provide employees with a rapid channel for reporting suspicious calls.</li></ul><p>In my view, the central lesson is that identity security cannot stop at MFA enrollment. Organizations must monitor what happens after authentication and treat helpdesk procedures as privileged security controls. A trusted voice on the telephone should never be enough to authorize a change that can unlock an entire cloud environment.</p>

Nach oben