72 Fake Sites, One Phone Call: Vishing Hits Private Equity

Hackers called employees at some of the largest private equity firms. The MFA codes were typed into 72 spoofed sites.
Proof
August 24, 2026
72 Fake Sites, One Phone Call: Vishing Hits Private Equity

Over the course of a month, ransom-seeking hackers targeted dozens of prominent US financial institutions, including six of the largest private equity firms in the world. Reuters, working from Google threat intelligence data, documented the campaign in early August. The attackers did not send emails. They made phone calls.

Five of the six private equity firms targeted rank among the industry's ten largest by assets under management. A comparable list in commercial banking would be the four biggest retail banks in the country. This was not opportunistic spray against soft targets. It was a deliberate campaign against the top of an industry.

How the calls worked

The mechanics are almost mundane, which is the point.

Attackers called employees on their personal cellphones and posed as a coworker or an IT help desk technician. They walked the employee to a spoofed website. The employee entered their credentials. Then the employee entered their multi-factor authentication code.

Google identified 72 malicious websites built for this campaign, attributed to four groups operating as Redact, Pink, Falcon, and Helix, and possibly coordinating under a single umbrella using phishing-as-a-service infrastructure. Ransom demands ran from $750,000 to $3 million. One associated cryptocurrency wallet took in roughly $10 million in bitcoin in the first months of 2026.

Austin Larsen, a principal threat analyst at Google's Threat Intelligence Group, gave Reuters the reason plainly: "Really, it's a money thing."

The MFA code is the whole story

Read that sequence again. The employee had multi-factor authentication. They used it. They typed the code into a website the attacker controlled, and the attacker relayed it in real time.

This is the structural problem with every authenticator that produces something a person can read out loud or type into a box. A push notification, an SMS code, a rotating code from an authenticator app: all of them can be handed to an attacker by a cooperative, well-intentioned employee who believes they are talking to their own help desk. The control did not fail. It did exactly what it was designed to do, for the wrong person.

Email filtering offers nothing here either. No filter inspects a phone call placed to a personal cellphone.

Why private equity is worth the call

Attackers pick industries on financial calculation, and private equity concentrates several things worth calculating.

Firms move large sums on tight timelines across a wide network of portfolio companies, fund administrators, vendors, advisors, and limited partners. That produces a high volume of legitimate financial traffic between parties who rarely meet in person, which is exactly the cover a fraudulent instruction needs to look routine.

They also hold data with unusual extortion value. Confidential deal terms, portfolio company financials, and limited partner lists are not merely sensitive. They are leverage. A ransomware operator holding an LP roster is negotiating over something worth far more than the cost of decrypting a few file servers, which is why demands in this campaign landed in the seven figures rather than the five.

Speed is the vulnerability

Speed of fund movement is a cornerstone of this business. Capital calls, closings, and vendor payments run on deadlines that everyone involved treats as fixed.

A caller who understands that dynamic does not try to defeat a control. They convince an employee that the control is the problem. Verification is taking too long. The closing is at risk. The counterparty is asking why nothing has landed. Under that pressure, the person with authority to override a procedure does so, believing they are protecting the deal.

That is what separates social engineering from a technical attack. The request looks legitimate, sounds legitimate, and arrives precisely when the recipient is least able to pause.

What actually stops the call

The defense has to answer a question a phone call cannot: is this really you?

That requires identity bound to the person rather than to something they know or something they were sent. Three things follow from that:

  1. Biometric verification tied to a government issued credential at the moment of the request, so the person asking for a help desk reset is the person whose account is being reset. A face cannot be relayed to a spoofed site the way a six digit code can.
  2. Out of band verification that runs on a channel the attacker does not control, rather than confirming a caller inside the call they initiated.
  3. Cryptographic binding between the verified person and the specific transaction. A session proves someone got through the door. A signed authorization proves a verified person approved this payment, for this amount, to this account.

Proof builds this layer. Identity is verified once to NIST IAL2 standards, issued as a PKI backed credential, and reused at every high risk moment: a help desk reset, a change to wire instructions, a capital call release. Every event produces a tamper evident record of who was verified and what they approved. Proof has secured more than $150 billion in money outflows on that model.

The question for every firm that was called

The firms targeted in this campaign are not careless. They have security teams, written wire verification policies, and MFA deployed across the workforce.

What they did not have, and what almost no firm has today, is an authenticator that an employee cannot give away over the phone. Until that exists, the fastest route into a private equity firm remains the telephone.

If you'd like to see how Proof closes the identity gap behind vishing and wire fraud, you can book time with our team here.

graphic of envelop on a square

Subscribe to our newsletter

Related Articles