Ransom-seeking hackers have spent the past month phoning employees of some of Wall Street's biggest names — pretending to be their company's help desk and steering them to booby-trapped websites — according to a Reuters investigation based on Google and internet-intelligence data.

Google counted 72 malicious sites aimed at staff of firms including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's. In just five weeks the same operators built digital traps for more than 200 companies, among them Uber, Zillow and Levi Strauss, plus law firms Paul Hastings and Greenberg Traurig. Google tracks the groups under names including Redact, Pink, Falcon and Helix — brands used by the operation it calls UNC6671, formerly BlackFile.

The method is disarmingly simple: hackers call employees on their personal cellphones — sometimes displaying the real help-desk number — claim an urgent passkey or multi-factor authentication update, and harvest the fail-safe code live over the phone before hijacking the account. Google says some companies have already paid ransoms.

'Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,' said Lee Clark of the Retail and Hospitality ISAC. Google's Austin Larsen is blunt about the tactic: 'Sophisticated is not the right word. It is just really effective.'