Private equity firms have long been attractive targets for cybercriminals. They oversee large transactions, manage time-sensitive payments, and work across an extensive network of portfolio companies, fund administrators, vendors, advisors, and investors.
Now, attackers are using social engineering to get closer to the payment workflows that move those funds. A recent wave of attacks targeted firms including Blackstone, Apollo Global Management, KKR, Bain Capital, TPG, and Clearlake Capital using phone calls and convincing impersonation tactics to manipulate employees into providing access.
The motivation is straightforward. As Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, told Reuters, attackers generally select industries based on financial calculations, and their campaigns are often successful.
“Really, it’s a money thing.”
With access to email threads, deal details, and payment conversations, a fraudster can make changed wire instructions appear routine. They can manufacture urgency around a capital call, a closing, or a vendor payment, and exploit the pressure teams feel to keep business moving.
That is the danger of social engineering: the request may look and sound legitimate and arrive at exactly the moment someone is most likely to act without pausing.
Most firms have a policy requiring changed wire instructions to be verified. But a policy alone is not enough when employees are managing urgent payments, emails, calls, and approvals across multiple parties.
A purpose-built verification tool gives finance and operations teams a consistent way to confirm that funds are going to the right recipient before they leave the firm. It provides a defined workflow, the right visibility, and an auditable record of every verification step.
Conduit helps ensure a wire instruction is not trusted simply because it looks legitimate. It is independently verified, documented, and approved before funds move. When the stakes are this high, verification must be built into the way you work.