Industry News

Google Warns of Hackers Using Phone Calls and Fake Websites to Target Financial Firms

Crypto Briefing · 7 Aug 2026
Key Takeaway Train staff to verify unexpected phone requests and website links independently, especially anything asking for login details or urgent payments.

Google has disclosed a wave of attacks against US financial firms that relied on social engineering rather than technical hacking alone. Attackers reportedly used phone calls impersonating trusted contacts, combined with fake websites designed to trick employees into handing over credentials or access.

Once inside, the attackers demanded ransom payments in Bitcoin, a common tactic used to make transactions harder to trace. The incident highlights how financial organisations remain a prime target due to the value of their data and the potential for large payouts.

While this case involved large financial institutions, the same tactics—phone-based impersonation and convincing fake login pages—are increasingly used against smaller businesses that may have less staff training and fewer verification processes in place.

Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from Crypto Briefing. We link back to every original so you can read it yourself.