Google Warns: Hackers Calling Bank Employees to Breach and Extort U.S. Firms

TL;DR
- Google’s threat intelligence unit has documented a surge in vishing (voice phishing) campaigns where attackers impersonate IT support or trusted vendors to call financial firm employees, exploiting phone-based authentication weaknesses to breach networks.
- The attackers steal confidential client and corporate data, then extort victims by threatening public leaks, regulatory exposure, or financial ruin—often using the stolen information to launch secondary attacks on customers.
- Financial institutions are urged to adopt hardware security keys, enforce strict callback verification protocols, and implement zero-trust network access to mitigate the risk of these socially engineered intrusions.
When most people imagine a cyberattack, they picture lines of malicious code or a phishing email with a suspicious link. But Google’s security researchers are sounding the alarm about a far more analog—and insidious—threat vector: the direct phone call. In a newly detailed campaign, hackers are bypassing firewalls and endpoint detection by simply picking up the phone and calling bank employees, posing as IT support staff or trusted third-party vendors. The goal isn’t to trick someone into clicking a link; it’s to trick them into handing over the keys to the kingdom.
This isn’t a theoretical exercise. Google’s Threat Analysis Group (TAG) and Mandiant have tracked multiple clusters of activity targeting U.S. financial institutions over the past several months, with a clear pattern emerging: social engineering over voice calls, followed by data theft and extortion. The attacks are sophisticated, patient, and brutally effective.
How the Vishing Playbook Works
The campaign typically begins with reconnaissance. Attackers scour LinkedIn, corporate directories, and even press releases to identify employees in finance, HR, or IT helpdesk roles—people who are likely to answer a call and have access to sensitive systems. They also gather details about the company’s actual IT vendors, software platforms, and internal jargon to make their impersonation more convincing.
The first call often comes from a spoofed number that appears to be internal or from a known vendor. The "IT support" agent might claim there’s a critical security patch needed, or that the employee’s account has been locked due to suspicious activity. To "verify" identity, the attacker will ask for the employee’s one-time passcode (OTP) sent to their phone or corporate app—a common but dangerously flawed authentication method.
In a more elaborate variant, the attacker poses as a vendor who needs remote access to "troubleshoot a payment issue." They guide the employee through installing a legitimate remote desktop tool, then silently harvest credentials, MFA tokens, and session cookies. Once inside, they move laterally through the network, often disabling logging and creating backdoor accounts for persistent access.
Why Phone-Based Authentication Is the Weak Point
The crux of this campaign’s success lies in the vulnerabilities inherent to phone-based authentication. SMS-based OTPs are notoriously phishable because they are not tied to the physical device’s cryptographic keys—an attacker who convinces a user to read out a code over the phone can easily capture it. Even app-based authenticators (like Google Authenticator) are vulnerable to real-time interception if the user is socially engineered into revealing the temporary code.
Moreover, phone calls create a sense of urgency and authority that emails often lack. A human voice, especially one using the correct names, titles, and internal terminology, bypasses the critical thinking that most employees apply to suspicious emails. The attackers also exploit "push fatigue"—bombarding users with MFA push notifications until they accept one just to make the noise stop. When a fake IT support person calls and says, "I see you have a pending login request; please approve it," many employees comply without question.
Google’s researchers noted that these attacks specifically target the "human element" of the authentication chain. Even with robust endpoint security, a single employee convinced to approve a login or read out a code can undo months of defensive hardening.
The Extortion Phase: Data Held Hostage
Once inside, the attackers don’t simply deploy ransomware. Instead, they quietly exfiltrate massive volumes of data—client portfolios, social security numbers, transaction histories, and internal communications. This data becomes leverage. The extortion demands are not just for money; they often include threats to leak the data publicly, report the breach to regulators (which would trigger fines and lawsuits), or expose embarrassing internal communications to the press.
Google’s report detailed cases where attackers threatened to contact the bank’s clients directly, informing them that their personal financial data had been compromised, unless a ransom was paid. This dual-pronged threat—financial ruin via regulatory penalties and reputational destruction via public leaks—creates immense pressure on executives to pay quickly. In some instances, the attackers even offered a "subscription" service: pay a monthly fee to prevent future attacks.
The extortion is often automated, with attackers setting up dark web leak sites that count down to a public release. This psychological warfare is designed to force a rapid decision, leaving little time for incident response teams to investigate or negotiate.
What Financial Institutions Must Do Now
Google’s researchers are not just describing the problem; they are offering a clear mitigation playbook. The first and most critical step is to eliminate phone-based OTPs entirely. Financial institutions should mandate FIDO2-compliant hardware security keys (like YubiKeys) for all employees, especially those with administrative or high-value access. These keys use public-key cryptography and are immune to vishing because there is no code to read out or approve over the phone.
Second, institutions must implement strict callback verification protocols. Any call claiming to be from IT or a vendor should be terminated, and the employee should hang up and call the official published number for that department or vendor. No exceptions. This simple step breaks the attacker’s real-time control of the conversation.
Third, adopt zero-trust network access (ZTNA) principles. This means continuously verifying every user and device, regardless of whether they are inside the corporate perimeter. Access to sensitive systems should be granted on a least-privilege basis, with session monitoring for unusual behavior, such as large data downloads or logins from unexpected locations.
Finally, security awareness training must evolve to include "vishing drills." Employees need to practice recognizing social engineering over the phone, just as they do with phishing emails. They should be trained to never provide passwords, OTPs, or remote access to unsolicited callers, and to report any suspicious calls immediately to a dedicated security hotline.
The threat is real, active, and growing. As Google’s researchers conclude, the financial sector’s greatest vulnerability is not its firewalls—it’s the trust its employees place in a familiar voice on the other end of the line. Rebuilding that trust with rigorous, verifiable processes is the only way to stay ahead of this new wave of digital extortion.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!