Major Wall Street hedge funds have been targeted in a coordinated wave of sophisticated cyberattacks, with hackers using voice phishing techniques to attempt to breach information systems at some of the industry’s largest money managers.
Point72 Asset Management, the $34 billion fund led by Steven Cohen, informed investors on Wednesday that it had been attacked, though initial indications suggested no client information was stolen. The firm said it was still reviewing the incident, according to Bloomberg News, which first reported the attacks.
Attackers also attempted to infiltrate information systems at Millennium Management, which manages roughly $70 billion in assets, and Two Sigma Investments, another quantitative trading giant. The scope of the attempts across multiple firms suggests a coordinated campaign rather than isolated incidents.
The attacks employed voice phishing, also known as vishing, in which criminals call employees impersonating colleagues or IT support staff to trick them into revealing credentials or installing malicious software. The technique has grown increasingly popular among sophisticated threat actors because it bypasses email security tools and targets the human element directly.
The targeting of multiple hedge funds in rapid succession raises questions about whether the attackers were seeking trading intelligence, client data, or financial information that could be used for market manipulation or extortion. Hedge funds hold some of the most sensitive financial data in the industry, including proprietary trading strategies and positions.
The attacks come amid a broader escalation in cyber threats targeting the financial sector. The FBI and cybersecurity agencies have warned of increasing sophistication in attacks on financial institutions, with state-sponsored and criminal groups both targeting the sector for espionage and profit.
Financial firms have long been prime targets for hackers due to the high value of the data they hold and the potential for direct financial gain. The hedge fund industry, with its concentration of wealth and sensitive trading information, represents an especially attractive target for both criminal organizations and nation-state actors.
The incidents highlight ongoing vulnerabilities in the financial sector despite years of investment in cybersecurity. Voice phishing remains effective because it exploits human trust rather than technical vulnerabilities, making it difficult for traditional security tools to detect and block.
discussion