Wall Street Hedge Fund Giants Targeted in AI-Powered Voice Phishing Campaign
Point72, Two Sigma, Citadel, and Millennium among major investment firms targeted in sophisticated cyber attack wave.
A coordinated wave of AI-driven voice phishing attacks has targeted several of Wall Street’s largest investment managers in recent days, exposing the hedge fund industry’s vulnerability to increasingly sophisticated cyber threats.
The assault hit major multi-strategy hedge funds including Two Sigma Investments, Point72 Asset Management, Citadel, and Millennium Management, as well as several private equity firms. Scammers used voice phishing, or “vishing,” leveraging technology to clone human voices in phone calls and messages to deceive employees into granting administrative access or sensitive financial credentials.
Point72 informed investors on Wednesday that it was targeted in the breach, noting that initial findings indicated no client information had been stolen while an internal review remains underway. Two Sigma, which manages $75 billion in assets, confirmed that its defenses successfully blocked the intrusion.
“Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a spokesperson for Two Sigma said in a statement. “We continue to monitor the situation closely.”
Spokespeople for Point72, Citadel, and Millennium declined to comment on the incidents.
The attacks illustrate how rapid advancements in artificial intelligence are lowering the cost and expanding the reach of cyberattacks across the financial sector. “Before they could attack 50 entities in a targeted attack, now they can do 1,000,” said Vinod Paul, president of Align Managed Services, an IT firm specializing in hedge fund cybersecurity. “Hackers can also listen into a phone call and mimic the voice, tone and phrasings of the speakers to create fake calls.”
In response to the surge in attempted breaches, the Financial Industry Regulatory Authority has been in direct contact with member firms to evaluate threat levels. The self-regulatory body established the Financial Intelligence Fusion Center in March, a secure portal designed for financial institutions to share real-time threat intelligence and coordinate countermeasures. A FINRA spokesperson declined to comment.
The hedge fund campaign coincides with broader corporate cyber threats identified across professional services. In June, Google’s cybersecurity unit reported a surge in vishing schemes targeting law firms, where attackers occasionally entered corporate headquarters posing as IT support technicians. Concurrently, U.S. officials have faced attacks targeting municipal water infrastructure in multiple states.
“The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale,” said Will Wilson, chief executive officer of Antithesis, an IT vulnerability detection firm backed by Jane Street. “Everybody will have to seriously level up. Otherwise they are going to be in big trouble.”









