Google's Threat Analysis Group (TAG) has issued a critical warning regarding a new wave of cyberattacks targeting the financial services sector. Investigations have revealed that hackers are employing sophisticated voice phishing (vishing) techniques, directly calling employees of financial institutions to gain unauthorized access to internal systems and extort funds.
This alert, based on the latest security trends report rather than a product announcement, highlights how threat actors weaponize information. Hackers leverage professional networking sites like LinkedIn to aggregate granular personal data on target employees. By impersonating project members or colleagues, they build rapport and manipulate victims into disclosing sensitive internal information, installing malicious software, or entering credentials into fraudulent portals.
Unlike traditional email-based phishing, the primary threat here lies in the use of live voice communication, which significantly increases the risk of social engineering success. To counter these human-centric attacks, Google strongly recommends that organizations implement comprehensive security awareness training, enforce mandatory multi-factor authentication (MFA), and establish strict verification protocols for any requests made via telephone.