Some of the most sophisticated firms in finance are being hunted with one of the oldest tricks going: a phone call. A voice-phishing campaign has swept through a roster of Wall Street’s biggest names, and the target list reads like a finance directory.
It takes in the private-equity giants Blackstone, KKR and Apollo, the exchange operator CME, and hedge funds such as Point72, Citadel, Millennium and Two Sigma.
Law firms were in the crosshairs too, with Paul Hastings and Greenberg Traurig, both of which handle sensitive deal and litigation work, caught up in the same sweep.
The method itself is deceptively low-tech. Attackers call employees’ personal mobiles, spoofing numbers to impersonate corporate IT, and insist that an urgent passkey or multifactor-authentication update has to be completed that day.
The trap waiting at the end of the call is a fake login page: victims are steered to lookalike domains, where an adversary-in-the-middle proxy quietly harvests their passwords and session tokens as they type.










