A concentrated wave of sophisticated cyberattacks has aimed at some of Wall Street's largest money managers in recent days, according to people familiar with the situation. The campaign used AI-enabled voice-cloning and other vishing techniques to impersonate trusted executives and attempt to persuade employees to reveal sensitive information or open pathways into corporate systems.
The intrusions targeted major hedge funds and several private equity firms. Named among the institutions reportedly approached were Two Sigma Investments, Citadel, and Point72 Asset Management. Firms across the sector have been working to mitigate the incidents and shore up defenses as the campaign unfolded.
How the attacks worked
The attackers relied primarily on voice phishing - commonly called "vishing" - which leverages audio technology and artificial intelligence to reproduce the voices, inflections, and phrasing of real executives or colleagues. These fabricated audio calls or messages were used to pressure staff into divulging credentials, sensitive information, or authorizing access to internal networks.
Responses from named firms
- Two Sigma Investments: The asset manager, which manages about $75 billion, confirmed that it stopped an attempted breach. A spokesperson said the firm's security team acted quickly in response to a vishing campaign affecting the firm and others, and stated there is "no indication of any impact to our data or our systems."
- Citadel and Point72: Representatives for both firms declined to say whether their systems had been targeted or breached.
Sector-level context
Industry observers said the recent assaults reflect a wider uptick in cyber threats affecting professional services over the past year. Firms facing these campaigns have focused on immediate containment and neutralization efforts while evaluating any exposure or operational implications.
Security teams across the targeted organizations have emphasized rapid incident response and communications with staff to reduce the likelihood that employees will be manipulated into providing access or sensitive information. At least one named firm reported a successful defensive outcome; others offered no public confirmation of impact when asked.
The situation underscores the evolving attack surface organizations must manage as audio-synthesis tools grow more capable, and it highlights why firms handling sensitive financial information are prioritizing detection, response, and employee awareness measures.