Google's security team has documented a coordinated hacking campaign targeting major U.S. financial institutions. The attackers use phone calls to employee targets as entry points, gaining access to steal sensitive customer data and launch extortion schemes against victims.

The campaign represents a shift in tactics from purely technical attacks to social engineering at scale. Hackers identify and contact financial firm employees, using manipulation or coercion to obtain credentials or system access. Once inside, they exfiltrate data and threaten to release it unless victims pay.

Google's researchers did not name the specific financial firms targeted, but the breadth of the campaign suggests multiple institutions across the sector face pressure. The attackers operate in organized groups with clear operational structure, indicating professional criminal enterprises rather than lone actors.

This approach exploits a persistent vulnerability in corporate security: humans. Even firms with robust technical defenses fall when attackers target employees directly through calls rather than emails or phishing links. Financial services represent high-value targets due to access to customer data and the sensitivity of information involved.

The findings highlight why financial firms invest heavily in security awareness training and multi-factor authentication beyond passwords alone. Phone-based attacks prove harder for automated systems to catch than digital intrusions, requiring behavioral detection and employee vigilance.

Google released the research as part of its ongoing threat intelligence sharing with the security community. The company regularly publishes findings about coordinated hacking groups to help other organizations understand emerging threats and strengthen defenses. Financial sector firms now face pressure to reassess employee security protocols and implement call verification systems that block impersonation attempts.

The campaign underscores why social engineering remains one of the most effective attack vectors against even well-defended organizations. Attackers know technical security improves constantly, but employee behavior changes slower.