Loading market data...

Google Warns of Phone and Fake Website Attacks on US Financial Firms

Google Warns of Phone and Fake Website Attacks on US Financial Firms

Phone calls and fake websites

The scheme starts with a phone call. The attacker poses as someone the target trusts, perhaps a vendor or an internal IT contact. They then direct the victim to a fake website designed to look exactly like a legitimate service. Once the victim enters their credentials, the attackers are in. Google's report doesn't name the firms hit, but the pattern is consistent: a call to build trust, a site to capture the login.

Bitcoin ransoms

Once inside, the attackers demanded payment. Google said the ransoms were paid in Bitcoin, a common choice for cybercriminals because crypto transactions are difficult to trace. The company didn't disclose how much was paid or how many companies were affected. The fact that any payment was made shows the scams worked.

What the attacks show

The incidents point to a persistent weakness in the financial sector: the human element. Google said the attacks highlight how vulnerable financial firms are to social engineering, and the company is calling for enhanced cybersecurity measures. That means stronger identity verification, more rigorous employee training, and a culture of skepticism when someone asks for access over the phone.

For now, the most effective defense might be the simplest: hang up, and call the person back on a number you know. Google