4 Sources
[1]
Big US hedge funds hit by wave of cyber attacks
Several of the biggest hedge funds on Wall Street have been hit by a wave of cyber attacks, putting the industry on high alert to the risk of vulnerabilities in their software systems. Billionaire Steve Cohen's Point72 and Ken Griffin's Citadel were among the hedge funds that were targeted by audio "phishing" attacks, attempts to obtain private information through phone calls and similar means, in recent days, according to people familiar with the matter. Millennium Management was also targeted by cyber attacks, according to a person familiar with the matter. All of the firms run complex risk systems with confidential trading information and manage tens of billions of dollars, making them prime potential targets for cyber criminals. Point72 was investigating the incident and trying to determine whether their systems were breached, according to one person familiar with the matter. It has contacted law enforcement and hired cyber security experts. The hedge fund also emailed investors on Wednesday to inform them that it did not believe any client information had been stolen. Citadel did not appear to be breached in the attack, according to other people familiar with the matter. One of the people highlighted that phishing attacks were common, but that the number of attacks had increased recently. All of the firms declined to comment. Bloomberg first reported the attempted attacks at some of the firms. At least some of the incidents involved voice phishing scams, in which the perpetrator impersonated a trusted person or colleague through phone calls or other audio communication, according to the people. It was not clear who was behind the attacks, or if they were co-ordinated by a single group. At one of the hedge funds, cyber criminals impersonated the firm's help desk, according to one person familiar with the matter. They contacted employees to try to gain login credentials for their authenticator apps, which serve as an additional layer of security in accessing a company's software system beyond usernames and passwords. The incidents come as governments and companies are racing to respond to the launch of AI tools that have made it easier for cyber criminals and state-backed groups to hack targets. Frontier AI models, in particular, have supercharged a cyber arms race as malign actors develop new abilities to attack while companies and governments seek new ways to defend themselves. A cyberdefence group at Google published a report in June detailing a similar series of incidents at law firms and financial institutions, in which the attackers also used phone calls to mimic IT employees. Wall Street groups have poured resources into beefing up their own cyber security systems in recent years, as AI has heightened the possibility that even unsophisticated actors could successfully hack into a company's network.
[2]
AI-Powered 'Vishing' Attacks Reportedly Targeted Top Hedge Funds
Amid all the recent reports of AI systems autonomously going off the rails and hacking into third-party organizations, it's almost easy to forget that human hackers are still out there, experimenting with AI in all kinds of nefarious ways. A new report from Bloomberg, however, is a reminder of just how quickly AI-enabled cybercrime is evolving -- and how unprepared the world is to deal with it. According to the report, a litany of high-profile hedge funds, including Citadel and Two Sigma, were targeted by recent voice phishing, or "vishing," attacks, in which AI is used to simulate the voices of actual humans in an attempt to skirt security systems. Several private equity firms were also reportedly targeted. Two Sigma told Bloomberg that it caught the attack in time before any of its internal systems could be compromised; Citadel and Point72, another hedge fund included in the attack, did not immediately respond to Gizmodo's request for comment. IT experts have been warning for years that the proliferation of cheap, easy-to-use AI tools that mimic human speech or generate other kinds of deepfake content will escalate both the severity of scam attempts and the rate at which they occur. The world got a taste of this in 2024, when an employee at the Hong Kong branch of a multinational company was duped into wiring more than $25.5 million to scammers who had instructed her to do so using AI-generated deepfakes of company employees, including its chief financial officer. AI scams are also being deployed to tip political scales. Last summer, for example, someone (or a group of people working together) used AI to recreate the voice of Secretary of State Marco Rubio and then sent voice messages to foreign diplomats and federal officials. OpenAI also said in a June report that a fleet of scammers, all of whom appear to have been backed by the Chinese government, had been illicitly using ChatGPT to generate inflammatory social media content aimed at fueling Americans' resentment towards data centers, the power cells of the United States' AI industry. All the while, the market pressures of the AI race -- combined with a total lack of federal regulation -- have been pushing tech developers to build increasingly capable models, including ones designed to imitate human speech. (Such tools are often promoted as "companions" that can alleviate loneliness, even though research has indicated they can sometimes have the opposite effect.) OpenAI's latest voice model, GPT-Live-1, is engineered to imitate subtle nuances of human speech, and, in theory, make interacting with AI feel less awkwardly mechanical. By design, OpenAI's model cannot imitate the voices of real people; that was a lesson OpenAI had to learn the hard way after it received earlier public blowback for releasing a voice model that, to many people's ears, sounded a lot like Scarlett Johansson. This is all to say: Nobody should be surprised that vishing attacks are on the rise. Technologically-enabled scam artistry is a tale as old as time, and AI is arguably the most enabling tool ever invented in that regard. The real mystery is why more isn't being done to build actually effective safeguards into AI systems to prevent them from happening in the first place.
[3]
Hackers Targeted Major Wall Street Money Managers With Cloned Voices. A $75 Billion Hedge Fund Stopped Them
In recent days, a string of coordinated cyberattacks has hit several major Wall Street money managers. The attacks used voice phishing, a technique that relies on technology to mimic voices in phone calls or messages, tricking employees into handing over sensitive information or granting system access. "Unlike traditional phishing, AI-powered voice attacks are drastically harder to detect," George Gerchow, chief security officer at Bedrock Data and faculty at IANS Research, told Inc. "By harvesting vast amounts of personal data from social media and the web, AI can accurately mimic a target's voice, interests, and behavior to craft convincing deepfakes." The scheme didn't stop there. Attackers also went after a number of high-profile firms, including Millennium Management, Two Sigma Investments, and Citadel. Two Sigma, which manages $75 billion in assets, confirmed it stopped the attempt before any sensitive data was accessed. "Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems," a spokesperson for the company said in a statement to Bloomberg. "We continue to monitor the situation closely."
[4]
Wall Street's Biggest Hedge Funds Targeted by Hackers in AI Voice Scam - iShares Cybersecurity and Tech E
Hackers launched a coordinated wave of attacks against some of Wall Street's largest hedge funds in recent days, using AI to mimic employees' voices and trick staff into granting system access, according to a Bloomberg report published Wednesday. Inside the Target List Two Sigma Investments confirmed it was targeted in an attempted vishing (voice phishing) campaign. "Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems," Two Sigma said in a statement, per Bloomberg. Ken Griffin's Citadel and Steve Cohen's Point72 Asset Management were also targeted, though spokespeople for both firms declined to say whether hackers actually breached their systems. Several unnamed private equity firms faced similar attempts, per Bloomberg. The attackers allegedly used technology capable of listening to phone calls and then replicating a speaker's voice, tone and phrasing to fabricate convincing fake calls. Regulators are already responding. The Financial Industry Regulatory Authority (FINRA) launched its Financial Intelligence Fusion Center in March, giving members a channel to share fraud intelligence and coordinate responses to sophisticated threats. A FINRA spokesperson declined to comment on the specific incident but confirmed contact with affected firms, according to Bloomberg. The Bigger Cybersecurity Reckoning Will Wilson, CEO of IT security firm Antithesis, argued financial firms benefited for decades from the scarcity of hacking expertise. Modern AI has "commoditized" that skill set, he said, pushing hedge funds and other firms toward urgent security upgrades or serious consequences. "The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale," Wilson said, according to Bloomberg. "Everybody will have to seriously level up. Otherwise they are going to be in big trouble." No confirmed breaches, stolen data, ransom demands or financial losses have been publicly disclosed from this specific campaign. The stakes remain high given that Wall Street firms process trillions of dollars in daily transactions, and AI allows for easier access to cyberweapons against even the most sophisticated financial institutions. Market News and Data brought to you by Benzinga APIs To add Benzinga News as your preferred source on Google, click here.
Share
Copy Link
Several top hedge funds including Citadel, Point72, Two Sigma, and Millennium Management were targeted by sophisticated audio phishing scams using AI-powered voice cloning technology. The coordinated cyber attacks attempted to trick employees into revealing login credentials by impersonating trusted colleagues and IT staff.
Several of Wall Street's largest hedge funds became targets of a coordinated wave of cyber attacks in recent days, putting the financial sector on high alert. Citadel, founded by billionaire Ken Griffin, Point72 Asset Management led by Steve Cohen, Millennium Management, and Two Sigma Investments—which manages $75 billion in assets—were all targeted by sophisticated audio phishing scams
1
3
. These firms run complex risk systems containing confidential trading information and manage tens of billions of dollars, making them prime targets for cyber criminals seeking to exploit vulnerabilities in their software systems.
Source: Gizmodo
Two Sigma confirmed its security team responded quickly to the attempted vishing campaign and detected no impact to its data or systems
4
. Point72 launched an investigation to determine whether their systems were breached, contacted law enforcement, and hired cyber security experts. The hedge fund emailed investors on Wednesday stating it did not believe any client information had been stolen1
. Citadel did not appear to be breached in the attack, though spokespeople for both Citadel and Point72 declined to provide further details4
.The attacks employed voice phishing, or vishing, a technique where perpetrators impersonated trusted colleagues through phone calls using AI-powered voice cloning technology
2
. At one hedge fund, cyber criminals impersonated the firm's help desk and contacted employees attempting to gain login credentials for their authenticator apps, which serve as an additional layer of security beyond usernames and passwords1
. The attackers allegedly used technology capable of listening to phone calls and replicating a speaker's voice, tone, and phrasing to fabricate convincing fake calls4
.
Source: Benzinga
George Gerchow, chief security officer at Bedrock Data and faculty at IANS Research, explained the severity of this AI-enabled cybercrime: "Unlike traditional phishing, AI-powered voice attacks are drastically harder to detect. By harvesting vast amounts of personal data from social media and the web, AI can accurately mimic a target's voice, interests, and behavior to craft convincing deepfakes"
3
. It remains unclear who orchestrated the attacks or whether they were coordinated by a single group1
.These incidents underscore the escalating cyber arms race as governments and companies race to respond to AI tools that have made it easier for cyber criminals and state-backed groups to hack targets
1
. A cyberdefence group at Google published a report in June detailing a similar series of incidents at law firms and financial institutions, where attackers used phone calls to mimic IT employees1
. The world witnessed the potential damage of such attacks in 2024, when an employee at a Hong Kong branch of a multinational company was duped into wiring more than $25.5 million to scammers using AI-generated deepfakes of company employees, including its chief financial officer2
.Wall Street groups have poured resources into strengthening their financial sector cybersecurity in recent years, as AI has heightened the possibility that even unsophisticated actors could successfully penetrate a company's network
1
. Will Wilson, CEO of IT security firm Antithesis, warned that modern AI systems have "commoditized" hacking expertise that was once scarce. "The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale. Everybody will have to seriously level up. Otherwise they are going to be in big trouble"4
.Related Stories
The Financial Industry Regulatory Authority, or FINRA, launched its Financial Intelligence Fusion Center in March, providing members a channel to share fraud intelligence and coordinate responses to sophisticated threats
4
. While a FINRA spokesperson declined to comment on the specific incident, they confirmed contact with affected firms. No confirmed data breaches, ransom demands, or financial losses have been publicly disclosed from this campaign4
.
Source: Inc.
The stakes remain extraordinarily high given that Wall Street firms process trillions of dollars in daily transactions, and AI allows easier access to cyberweapons against even the most sophisticated financial institutions
4
. The lack of federal regulation combined with market pressures of the AI race have pushed tech developers to build increasingly capable models, including ones designed to imitate human speech with subtle nuances2
. Watch for increased investment in authentication technologies, employee training programs focused on identifying vishing attempts, and potential regulatory frameworks addressing AI-enabled system compromises as the financial industry grapples with this evolving threat landscape.Summarized by
Navi
20 Jul 2026•Technology

10 Apr 2026•Policy and Regulation

13 Nov 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
