Citadel, Point72, and Two Sigma Targeted in Coordinated Wall Street Vishing Attack
- Firms targeted: Point72 Asset Management, Two Sigma Investments, Citadel, and Millennium Management were hit by sophisticated cyberattacks.
- Attack method: Hackers used vishing to mimic employees' and executives' voices, tricking staff into granting access or sharing sensitive data.
- One firm blocked it: Two Sigma confirmed it intercepted the attempt with no impact to its data or systems.
Hackers launched a coordinated wave of sophisticated cyberattacks against major Wall Street financial firms and money managers in recent days, using vishing to impersonate employees and executives, according to people familiar with the matter. Some of the world's largest hedge funds, along with several private equity firms, were among the targets.
Point72, Two Sigma, Citadel, and Millennium Attacks
Point72 Asset Management told investors on Wednesday that it had suffered a cyberattack, one of the sources said, cited by Reuters. The announcement said that the firm's initial review found no client information was stolen, though it told investors it was still reviewing the incident.
The hackers also attempted breaches at other major money managers, including Two Sigma Investments, Citadel, and Millennium Management, according to Bloomberg.
"Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” said Two Sigma, confirming the attack. We continue to monitor the situation closely."
Vishing Powers the Attack
The attacks relied on vishing (voice phishing), a technique that isn't new in concept, but security experts say AI has dramatically expanded its scale. Vinod Paul, president of Align Managed Services, described the shift bluntly: before AI, attackers might target roughly 50 entities at once; now, that same effort can reach a thousand.
Attempts to breach major financial institutions are considered routine by cybersecurity experts, but the use of AI-driven voice cloning marks an escalation in sophistication.
Regulators and the White House Respond
The Financial Industry Regulatory Authority (FINRA) has connected affected firms with threat intelligence through its newly launched Financial Intelligence Fusion Center, aimed at helping the financial sector share and act on emerging threat data.
Separately, the White House announced a working group earlier this year uniting AI developers and critical infrastructure operators, as global companies continue battling a broader surge in AI-powered cyberattacks and ransomware.
February reports said 1.4 million Betterment email addresses were exposed following a third-party social engineering data breach.
A June Mandiant report identified a financially motivated data theft extortion campaign executed by UNC3753 – aka Luna Moth, Chatty Spider, Storm-0252, and Silent Ransom Group (SRG) – targeting U.S. law firms in a vishing extortion campaign.
In the same month, the Pink extortion group, which was linked to UNC6671 and The Com, was seen using vishing and fake helpdesk calls to target enterprise data.





