The Wall Street Vishing Wave Shows Why MFA Is Not Enough

The Wall Street Vishing Wave Shows Why MFA Is Not Enough

Attempted attacks on major US investment firms put the helpdesk and identity provider at the centre of the threat model. Public reporting does not establish that every named target was breached.

Reuters reported on 5 August that hackers had attempted sophisticated cyberattacks against major Wall Street money managers and financial-services firms. The reported targets included Point72 Asset Management, Two Sigma Investments and Citadel, alongside private-equity businesses.

The attempts reportedly used phone calls in which criminals tried to persuade employees to grant access or disclose sensitive information. Point72 told investors it had faced an attack and, according to Reuters’ sources, said that no customer information was stolen. Public information did not establish a successful breach at every organisation named in the reporting.

That caution is important. A list of targets is not a list of victims. Even so, the campaign deserves attention because it concentrates on a control many organisations still treat as secondary: the process by which a person proves who they are to IT support.

Vishing attacks the recovery path

Voice phishing works because the caller can create urgency and borrow the authority of an internal support team. The attacker may claim that an account is under attack, that a security update is required or that the employee must visit a login page immediately.

In related campaigns documented by Google Threat Intelligence Group, criminals combined convincing calls with lookalike sign-in pages and adversary-in-the-middle infrastructure. That can capture not only a password but also an authenticated session or token, allowing an attacker to get past some forms of multi-factor authentication.

Once inside a cloud identity or SaaS account, the attacker can search email, SharePoint, Teams or other repositories, automate bulk data collection and use stolen internal accounts to make later messages appear more credible. Data theft then becomes leverage for extortion.

Google tracks one such operation as UNC6671, associated with the BlackFile name. The public reporting about the August Wall Street attempts did not conclusively attribute every attempted intrusion to that actor, so the activity should be treated as a pattern rather than a single confirmed campaign.

The helpdesk is a privileged interface

An organisation can deploy strong authentication and still leave a weaker reset or enrolment route beside it. If support staff can add a new MFA device, reset a password or approve remote access after a persuasive call, the helpdesk effectively holds administrative power over the identity system.

The solution is not to tell staff to “be more careful”. Verification must be designed so that a convincing voice, a familiar name and knowledge of internal details are insufficient.

Controls to review now

  • Require a callback through a trusted directory number for sensitive support requests; never use contact details supplied by the caller.
  • Introduce a second-person approval for MFA resets, new device enrolment and changes to privileged accounts.
  • Move administrators and high-value users to phishing-resistant authentication such as passkeys or hardware security keys.
  • Prevent a password reset from automatically preserving existing sessions; revoke tokens and review newly registered devices as part of containment.
  • Alert on unusual identity-provider enrolments, impossible travel, new forwarding rules and bulk downloads from Microsoft 365 or other SaaS platforms.
  • Separate everyday accounts from privileged administration and restrict where administrative sessions can originate.
  • Give support teams a short, rehearsed way to stop an urgent call without being penalised for delaying a genuine request.
  • Run vishing exercises that test the support and recovery process, not only the employee receiving the first call.

Financial institutions are attractive targets, but the lesson applies to any organisation with valuable cloud data. Identity security is only as strong as its least verified recovery path.

Sources and further reading

Named organisations’ exposure and attribution may change as investigations continue. Treat unconfirmed targeting and confirmed data loss as separate claims.

Leave a Reply

Your email address will not be published. Required fields are marked *