Google reports hackers targeting US financial firm employees for data theft and extortion
Google’s security research team has identified coordinated attacks by multiple hacker groups against major U.S. financial institutions, in which the perpetrators infiltrate corporate networks, exfiltrate sensitive customer and operational data, and then demand payment to prevent public disclosure. The campaigns, which began in early 2024, target banks, credit‑card issuers and investment firms, exploiting vulnerabilities in remote‑access tools and compromised third‑party software to gain privileged access.
According to the Google report, the attackers use encrypted command‑and‑control channels and custom ransomware to encrypt stolen files before issuing extortion demands, often threatening to release personally identifiable information or trade secrets. Several affected firms have engaged law‑enforcement agencies and initiated internal security reviews, while Google has shared indicators of compromise with industry partners to mitigate further intrusion. Investigations remain ongoing as authorities work to trace the actors and disrupt the illicit operations.