Hackers Create 72 Fake Websites Targeting Blackstone, KKR, and CME Employee Data

Regulation Impact 4
โดย Money & Banking·US·Read original
Summary · why it matters

A ransomware group attempted to attack dozens of major US financial and business firms by creating at least 72 fake websites to steal passwords and authentication data from employees at targeted companies such as Blackstone, Apollo Global Management, KKR, Bain Capital, Bridgewater Associates, TPG, CME Group, and Moody’s. The hackers called employees’ personal mobile phones, posing as IT support, and tricked them into updating passkeys or multi-factor authentication, then directed them to fake websites with credible-sounding names like “passkeyhelpdesk” or “secure-passkey.” Google said that over five weeks, the cybercriminal group set up digital traps for more than 200 companies, including non-financial firms like Uber, Zillow, Levi Strauss, and law firms Paul Hastings and Greenberg Traurig. In some cases, companies paid ransoms, but it has not been confirmed whether the attempted attacks on the named firms were successful.

Impact on stocks 9

Aging Population · 2 stocks
KKR & Co. Inc.
KKR
▼ NegativeRegulationrelevance

Targeted by ransomware group via fake websites to steal employee data

Artificial Intelligence · 1 stocks
Blackstone Group Inc
BX
▼ NegativeRegulationrelevance

Targeted by ransomware group via fake websites to steal employee data

Carbon Removal (DAC) · 1 stocks
CME Group Inc
CME
▼ NegativeRegulationrelevance

Targeted by ransomware group via fake websites to steal employee data

Cloud & Digital Infrastructure · 1 stocks
Moodys Corporation
MCO
▼ NegativeRegulationrelevance

Moody's is a target of a ransomware group's phishing attack, posing a cybersecurity threat.

Financials · 1 stocks
TPG Inc
TPG
▼ NegativeRegulationrelevance

TPG is a target of a ransomware group's phishing attack, posing a cybersecurity threat.

Robotics & Physical AI · 1 stocks
Uber Technologies Inc
UBER
▼ NegativeRegulationrelevance

Uber is mentioned as a non-financial firm targeted by the same cybercriminal group.

Real Estate · 1 stocks
Zillow Group Inc Class C
Z
▼ NegativeRegulationrelevance

Zillow is mentioned as a non-financial firm targeted by the same cybercriminal group.

Consumer Discretionary · 1 stocks

Theme Impact 2

Off-coverage companies 4

Bain CapitalPrivate▼ Negative
Regulationrelevance

Bain Capital is a target of a ransomware group's phishing attack, posing a cybersecurity threat.

Bridgewater AssociatesPrivate▼ Negative
Regulationrelevance

Targeted by ransomware group via fake websites to steal employee data

Greenberg TraurigPrivate± Mixed
relevance

Paul HastingsPrivate± Mixed
relevance

Related news

Japan's National Police Agency says North Korean IT worker applied for engineer job at bitFlyer

Japan's National Police Agency announced on September 18 that a person believed to be a North Korean IT worker applied in May 2025 for an engineer position at the domestic cryptocurrency exchange bitFlyer. The applicant attached a résumé to the recruitment form under someone else's identity and applied directly rather than through an intermediary, but the company noticed suspicious behavior and responded, so no hiring or damage resulted. According to the National Police Agency, the applicant accessed the recruitment form using multiple VPN services, listed a Gmail address as contact information, and stated in the résumé a broad range of skills in programming languages, blockchain, and cloud services, along with graduation from a European university and work experience in cities in Europe and Asia. In an online interview, the applicant said they were from Malaysia and living in Finland, but refused to relocate to Japan or work on-site, or said they would agree only if it were six months out, insisted on being paid in cryptocurrency, frequently checked another monitor during the interview, and at times another person's voice could be heard from behind. The National Police Agency and the U.S. Federal Bureau of Investigation believe that the cyberattack group WaterPlum's activities and some of the foreign-currency earning operations by North Korean IT workers are centrally linked to the Workers' Party of Korea's Bureau 313, and the IP addresses used by the group's attackers, the North Korean IT workers, and the applicant to bitFlyer matched.
NADA NEWS·23hRead more →
5

GPF Joins Forces with 3 Partners to Strengthen Online Fraud Protection for 1.2 Million Members

The Government Pension Fund, or GPF, has signed a memorandum of understanding with the Deposit Protection Agency, Gogolook (Thailand) Company Limited, known as Whoscall, and National ITMX Company Limited, known as NITMX, to strengthen awareness of fraud and digital crime among GPF members and the general public. Mr. Sornphon Tulyasathien, Secretary-General of the GPF Board, said the organisation manages retirement savings for more than 1.2 million members, and that this collaboration is part of the Retirement Academy project. Under the partnership, Whoscall is providing 1.5 million Whoscall Premium Basic licences to GPF members and will jointly develop an e-learning course with its partners. Mr. Sornphon noted that in 2026, about 16,000 GPF members will retire, with average savings of 1.5 million baht per person. Mrs. Piyaporn Phoklin, Deputy Director and Acting Director of the Deposit Protection Agency, disclosed that from mid-2024 to the present, there have been 270 complaints from people deceived by scammers posing as the agency, with elderly victims accounting for 30 to 40 percent, and 24 victims who actually lost money, with losses ranging from a few hundred baht up to 400,000 baht. Mr. Manwoo Joo, Chief Executive Officer of Gogolook (Thailand) Company Limited, said a single scam phone number can make more than 800,000 calls. Mr. Chatchai Dusadeenod, Managing Director of National ITMX Company Limited, said this collaboration will help broaden the fight against digital crime and reduce the number of victims.
InfoQuest·2dRead more →

Microsoft Opens Government AI Suite October 1 With Features Still Pending Accreditation

Microsoft has told federal buyers that a new top government tier of its productivity suite, plus a companion agent-management product, will be available for Government Community Cloud customers to purchase on October 1, with individual capabilities lighting up in phases as each workload clears its required government security accreditation. The new suite layers Copilot, identity and security tooling, and agent-governance controls on top of the prior government tier, with the headline addition being Agent 365, which Microsoft has framed on the commercial side as providing security operations, financial operations, and observability and manageability of token spending across business processes. Microsoft has not disclosed per-seat pricing for the new tier or paid conversion rates from earlier no-cost federal Copilot deployments, leaving any government revenue forecast impossible, and the stock closed at $497.12, down 2.74% over the past year. On the commercial side, net paid seats more than doubled sequentially to over 30 million Copilot seats, while full-year capital expenditures hit $115.95 billion and free cash flow fell 23.19% in the quarter. Analysts carry an average price target of $572.92 with 38 Buy and 14 Strong Buy ratings, and the variable that decides the bull and bear cases is what Microsoft discloses in coming quarters about paid government seat counts and workload authorization progress rather than the October launch itself.
24/7 Wall St·2dRead more →