Logo

Jooish

HomeSitesGroupsStatus
Sign InSign Up
HomeSitesGroupsStatusSign In
JBizNews

Top Hedge Funds Hit by Wave of Attempted Cyberattacks

Aug 5, 2026·4 min read

Point72 Asset Management told investors Wednesday that it had been attacked by hackers, with initial indications that no client information was stolen and the firm still reviewing the incident, according to a person familiar with the matter.

The Stamford, Connecticut firm was not alone. Attackers tried to breach information systems at Two Sigma Investments and Citadel as well, and several private equity firms were targeted in the same assault. Millennium Management was also among the money managers hit. That puts three of the largest names in New York and Connecticut asset management inside a single coordinated campaign.

The method

The attack ran on voice phishing, or vishing, in which criminals use technology to mimic voices on phone calls or messages and pressure employees into handing over sensitive information or granting access. The technique leans on artificial intelligence to reproduce the exact voice, tone, and phrasing of a real executive or colleague, so that an employee believes they are taking a call from someone they know.

There is no malware to catch and no suspicious link to hover over. The point of entry is a human being answering a phone.

Two Sigma, which manages about $75 billion, said its security team responded quickly to a vishing campaign aimed at the firm and others, and that there was no indication of impact to its data or systems. Spokespeople for Citadel and Point72 declined to comment on whether their systems were targeted or breached.

Why it scaled

The economics of the attack are the story for every business owner reading this, not just for funds with compliance departments the size of a small company.

Vinod Paul, president of Align Managed Services, which handles cybersecurity and information technology for hedge funds, said breaches on Wall Street have surged over the past year as artificial intelligence tools let bad actors attack cheaply and broadly. Where an attacker could once target 50 entities, Paul said, they can now hit 1,000 — and can listen to a phone call and imitate the speaker’s voice, tone, and phrasing to build fake calls.

That is a twenty-fold expansion in reach at roughly the same cost. It is the same curve that made AI attractive to legitimate businesses, running in the other direction.

Not confined to finance

A Google cybersecurity unit published a post in June describing a wave of attacks this year on law firms and other professional services companies. Those attacks also used vishing, and in some cases involved people walking into corporate offices posing as information technology workers.

The Financial Industry Regulatory Authority, which oversees broker dealers and securities professionals, has been in contact with member firms about the recent attempts.

Break-in attempts against major financial institutions are routine, and the phone-call approach persists because it works. It has been used successfully by groups such as Scattered Spider, a loose collection of young hackers with a long list of corporate victims in recent years.

What this means for the tri-state business owner

The firms named this week spend more on information security in a quarter than most regional companies earn in a year, and the attackers still got far enough to force disclosure to investors. That should reframe how a mid-sized distributor, medical practice, or family real estate office thinks about its own exposure.

The controls that matter here are not expensive. They are procedural:

Call-back verification. No wire transfer, credential reset, or vendor bank-detail change gets executed on the strength of a voice on the phone. The employee hangs up and calls back on a number already on file — not one supplied during the call.

A code word for financial instructions. Low-tech, and effective precisely because a synthetic voice cannot produce information it never had access to.

Train the front line, not just the finance team. These campaigns often start with a help-desk call or a receptionist, not the controller.

Assume the voice is fake. The old advice was to listen for something off in the audio. That advice is expired.

The broader cost

For the funds, the immediate damage appears limited — Two Sigma detected and blocked the attempt with no evidence of a breach. The lasting cost is elsewhere. Every incident of this kind adds to compliance spending, insurance premiums, and vendor due-diligence requirements that eventually flow down to the smaller firms doing business with them.

Any company that sends invoices to a large institution should expect tighter identity verification on its own end in the coming months. That is not bureaucracy for its own sake. It is what happens after a campaign like this one reaches the investor-notification stage at a firm the size of Point72.

JBizNews Desk | New York

© JBizNews.com All Rights Reserved. Reproduction or distribution without written permission is prohibited.

View original on JBizNews