Key Takeaways
- Point72 Asset Management reported an attack, while Two Sigma Investments said it blocked an attempted vishing campaign without detected impact to its data or systems.
- Millennium Management and Citadel were also reportedly targeted as attackers used voice impersonation and social engineering to seek access.
- The campaign shows why hedge funds are expanding identity controls, employee verification procedures and oversight of third-party providers.
A coordinated cyber campaign has put some of Wall Street’s largest hedge funds on alert, with attackers reportedly targeting Point72 Asset Management, Two Sigma Investments, Millennium Management and Citadel through voice phishing.
Point72 Asset Management informed investors on August 5 that it had been attacked, according to Bloomberg reporting carried by WSAU. Initial indications suggested that no client information had been stolen, although Point72 was still reviewing the incident. Spokespeople for Point72, Millennium Management and Citadel declined to comment.
Two Sigma Investments, which oversees $75 billion in assets, said its security team stopped an attempted vishing campaign aimed at Two Sigma and other investment managers. Two Sigma said it had no indication that its data or systems were affected and was continuing to monitor the situation.
Vishing involves attackers using phone calls or voice messages to persuade employees to disclose credentials, approve authentication requests or grant access to internal systems. Generative artificial intelligence can make those attempts cheaper and more convincing by reproducing a person’s voice, tone and phrasing from relatively small samples.
The president of Align Managed Services described the change in scale bluntly: “Before they could attack 50 entities in a targeted attack, now they can do 1,000.” That volume gives criminals more chances to find one employee, contractor or service provider who reacts before checking whether a request is legitimate.
Because hedge funds already spend heavily on technical defenses, attackers often target the human workflow surrounding password resets, help-desk calls, vendor access and urgent requests from senior executives. A familiar voice can weaken the skepticism that would normally greet an unusual email.
Industry data reflects this pressure. A Hedge Fund Association and SeaGlass Technology survey, reported by Cybersecurity Dive, found that 80% of hedge funds and investment firms increased cybersecurity spending in 2025. Even so, about half reported at least one breach during the preceding 12 months, while two-thirds identified phishing as a leading concern.
Roughly half of the incidents covered by that research were linked to third-party risk. This widens the attack surface beyond the hedge fund itself to law firms, fund administrators, technology providers and other professional-services partners holding sensitive information or trusted access.
That concern is not theoretical. In June, Google Threat Intelligence Group described a campaign targeting US law firms and professional-services businesses through social engineering. Reported tactics included vishing and, in some cases, people physically entering offices while posing as IT personnel. Could a convincing caller exploit the same trusted relationships connecting a fund with its outside counsel or administrator? That is precisely the scenario security teams now have to test.
The Financial Industry Regulatory Authority has also been communicating with member firms about attempted breaches. In March, Finra launched its Financial Intelligence Fusion Center, a secure portal intended to support intelligence sharing and coordinated responses to fraud and cyber threats.
For security leaders, the response extends beyond another awareness course. High-risk support requests can benefit from callback procedures using independently verified numbers, phishing-resistant authentication and separate approval paths for account recovery. Firms can also restrict help-desk privileges, record sensitive administrative actions and rehearse incidents involving convincing voice impersonation.
Third-party access deserves similar scrutiny. Time-limited permissions, network segmentation and clear notification requirements can reduce the damage if a partner is compromised. Alignment with the NIST Cybersecurity Framework and guidance from national cybersecurity authorities can help funds organize those controls around identification, protection, detection, response and recovery.
The latest campaign did not produce a publicly confirmed data loss at Two Sigma Investments, and Point72 Asset Management’s initial review found no indication that client information had been stolen. Still, attackers do not need to defeat every control. They need one believable conversation. For hedge funds handling valuable strategies, investor records and market-sensitive operations, voice identity can no longer serve as proof of identity on its own.
⬇️