Hackers Are Calling Financial Firms’ Help Desks

Hackers do not need a zero-day when they can sound confident on the phone. That is the uncomfortable lesson from Google’s latest warning, highlighted by TechCrunch’s report that threat actors are calling financial-firm employees as part of intrusion and extortion campaigns.
The takeaway: voice phishing is no longer a soft consumer scam; it is an enterprise access strategy aimed at the people who can reset, approve, or escalate.
What Google says is happening
According to the report, Google warned that hackers are using phone calls to trick employees at financial firms, with the goal of gaining access and then extorting victims. The pattern is familiar to incident responders: attackers impersonate trusted internal teams, create urgency, and guide a target through steps that hand over access.
This kind of attack is often called vishing, short for voice phishing. It sits inside the broader social-engineering playbook, but the phone gives attackers something email rarely can: real-time pressure, rapport, and the ability to adapt when a target hesitates.
Google has previously documented how financially motivated groups use social engineering against help desks and identity systems, including in its hardening recommendations for UNC3944 activity. The tactics vary, but the business model is consistent: get inside, find valuable data or systems, and use the threat of disruption or disclosure to force payment.
Why the help desk is the new perimeter
Financial firms have invested heavily in endpoint security, fraud monitoring, identity tooling, and network controls. That has raised the cost of purely technical intrusion, so attackers look for workflows where humans are expected to be helpful, fast, and flexible.
Help desks are especially attractive because they sit near the keys to the kingdom. A well-meaning support agent may be able to reset a password, enroll a new device, change a multi-factor authentication method, unlock an account, or escalate a ticket to someone with broader privileges.
The danger is not that employees are careless. It is that many support processes were designed for availability first and adversarial abuse second. In banking and financial services, where downtime is costly and executive users expect urgent service, attackers can weaponize the culture of responsiveness.
The Verizon Data Breach Investigations Report has repeatedly shown the importance of the human element in breaches. Voice attacks exploit that same reality, but with a channel that many organizations monitor less aggressively than email, web traffic, or endpoint behavior.
How vishing turns into extortion
A phone call is usually just the opening move. Once an attacker convinces an employee or help-desk agent to take an action, the campaign can quickly shift from impersonation to account takeover.
From there, the attacker may search email, customer systems, cloud storage, SaaS applications, or internal ticketing tools. In a financial firm, those environments can contain sensitive customer data, transaction records, deal materials, employee information, credentials, and operational details that create leverage.
Common pressure points include:
MFA resets: Attackers persuade support teams to replace or re-enroll authentication factors.
Device enrollment: A rogue device is added as if it belongs to a legitimate employee.
Password recovery: Account recovery flows are abused when identity proofing is weak.
SaaS access: Compromised accounts are used to pull data from CRM, collaboration, or file-sharing tools.
Privilege escalation: Attackers use internal trust to reach admins, finance teams, or executives.
Data theft: Stolen records become the basis for extortion, regulatory pressure, or public leaks.
This is why vishing deserves board-level attention. The phone call may sound low-tech, but the downstream impact can be a full enterprise compromise.
What financial firms should do now
The practical response is not to tell employees to “be more careful” and move on. Financial firms need to redesign high-risk support workflows so a convincing voice is never enough to change access.
Start with identity proofing. CISA’s guidance on avoiding social engineering and phishing attacks emphasizes skepticism toward unsolicited requests and independent verification. In an enterprise setting, that means forcing sensitive help-desk actions through verified channels, not the channel the caller chose.
Financial firms should also review authentication recovery in light of NIST’s Digital Identity Guidelines. Recovery processes often become the weakest part of an otherwise strong identity program, because they are built to rescue locked-out users under time pressure.
Useful controls include:
Verified call-backs: Require support staff to call users back using a trusted directory number before sensitive changes.
Step-up approvals: Route MFA resets, device enrollments, and admin changes through a second approver.
No caller-led actions: Ban help-desk agents from following instructions delivered entirely by an inbound caller.
Ticket risk scoring: Flag urgent, executive, after-hours, or repeated recovery requests for review.
Session monitoring: Watch for impossible travel, new device fingerprints, and unusual SaaS exports after recovery events.
Drills and scripts: Train support teams with realistic vishing scenarios and approved refusal language.
The goal is to remove improvisation from the most dangerous moments. If a process is clear, logged, and enforced, an attacker has fewer chances to charm or pressure an employee into making an exception.
Security teams should also treat help-desk telemetry as security telemetry. Password resets, MFA changes, device enrollments, recovery codes, and privilege escalations should feed into detection pipelines just like endpoint alerts and suspicious logins.
The bottom line
The Google warning is a reminder that attackers follow the path of least resistance, and in many financial firms that path now runs through a phone call. Help desks are not back-office utilities; they are identity control points.
Banks, insurers, asset managers, and fintech companies should assume their support teams are being profiled and targeted. The firms that fare best will be the ones that make high-risk access changes verifiable by design, not dependent on whether someone sounds trustworthy.