Multiple major Wall Street financial services firms and asset managers were the focus of a coordinated series of attempted cyber intrusions in recent days, according to two people familiar with the matter who spoke on condition of anonymity. The efforts targeted information systems at some of the world’s largest hedge funds and several private equity firms, the sources said.
The apparent intrusion attempts relied heavily on phone-based social engineering. Attackers placed calls designed to trick employees into providing system access or surrendering sensitive information, the sources said. That method - which continues to be widely used because it can bypass technical controls by exploiting human behavior - figured prominently in the incidents described to the sources.
One firm that alerted investors was Point72 Asset Management, which, according to one of the people familiar with the matter, reported it had been the subject of a hack attempt. The firm indicated that no customer information was stolen during that episode, the source said.
Sources also said the hackers tried to breach information systems at other hedge funds, including Two Sigma Investments and Citadel. Two Sigma did not immediately reply to a request for comment. Citadel and Point72 declined to comment, the sources said.
Cybersecurity specialists note that attempts to penetrate major financial institutions are a recurring challenge. The phone-call approach remains effective and is employed by criminal groups; one loosely affiliated group often cited in reporting on similar tactics is known as "Scattered Spider," a loose-knit group of young hackers that has accumulated a list of corporate victims in recent years.
At the same time, companies worldwide are confronting a rise in cyberattacks that increasingly leverage artificial intelligence and ransomware to disrupt operations and exfiltrate data. In response to these evolving threats, the White House announced a working group earlier this year intended to bring AI developers together with operators of critical infrastructure to share intelligence and coordinate defensive measures.
Summary
Phone-based social-engineering attempts targeted major hedge funds and private equity firms. Point72 said it had been attacked and reported no customer data loss, while sources named Two Sigma and Citadel as other targets. The incidents occur amid a broader surge in AI-enabled cyber threats and coordinated policy responses.
Key points
- Attackers used phone calls to manipulate employees into granting access or divulging sensitive information, a tactic that remains effective.
- Point72 Asset Management reported an attempted intrusion and indicated no customer information was taken.
- Other firms cited by sources as targets include Two Sigma Investments and Citadel; public comments were limited.