The attackers relied on phone-based social engineering methods rather than traditional hacking tools to trick employees into giving up their login credentials. Among the firms whose staff were targeted are some of the biggest names in private equity and finance, including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group and Moody’s. How the Group Behind the Attacks OperatesGoogle identified the perpetrators as a hacking group that goes by several names, including Redact, Pink, Falcon and Helix. Reuters noted it was unable to independently confirm exactly which firms had actually been compromised in the campaign. When approached for comment, several of the named companies, including KKR, Bain Capital, CME Group, TPG and Apollo, declined to respond.