A cyberattack on Wall Street recently targeted several leading hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers used voice phishing, or “vishing,” to trick employees into revealing sensitive information or granting access to internal systems.
Cybersecurity experts say such attempts are common because financial institutions store highly sensitive data. However, the latest incidents highlight how cybercriminals are increasingly combining traditional social engineering tactics with artificial intelligence to make impersonation attempts more convincing.
Point72 Says No Client Data Was Compromised
According to reports, Point72 Asset Management informed investors on August 5 that it had been targeted in the latest cyberattack on Wall Street. Bloomberg first reported the communication, citing a source familiar with the matter.
The firm said it was reviewing the incident and that no client information had been stolen. Point72 declined to comment publicly.
The campaign extended beyond Point72, with hackers also attempting to breach the information systems of Millennium Management, Two Sigma Investments, and Citadel, according to sources.
Voice Phishing Remains an Effective Attack Method
The attackers relied on voice phishing, a social engineering technique in which criminals impersonate trusted individuals—often IT support staff—to persuade employees to disclose confidential information or provide system access.
Cybersecurity experts told Reuters that these attacks are routine because of the valuable information held by financial firms. Rather than exploiting software vulnerabilities, voice phishing succeeds by manipulating human behaviour.
The tactic has also been used successfully by the cybercriminal group “Scattered Spider,” a loosely organized network of young hackers that has targeted numerous companies in recent years.
AI Is Increasing the Sophistication of Cyberattacks
Security experts say the attempted cyberattack on Wall Street demonstrates how artificial intelligence is making social engineering campaigns more persuasive and difficult to detect.
A similar trend was highlighted in June, when Google’s cybersecurity unit published a report detailing a campaign targeting U.S. law firms and other professional and financial services organizations.
According to the report, attackers posed as IT support personnel through voice phishing calls and, in some cases, even visited offices while pretending to be IT maintenance staff.
Growing Cyber Risks for Financial Firms
The attempted cyberattack on Wall Street comes as organizations worldwide face a rise in AI-powered cyberattacks and ransomware incidents that disrupt operations and steal sensitive data.
In response to the growing threat, the White House announced a working group earlier this year that brings together AI developers and critical infrastructure operators to share threat intelligence and strengthen cyber defenses.
Although Point72 said no customer information was compromised, the attempted attacks on several prominent hedge funds underscore the persistent cybersecurity risks facing the financial sector and the increasing use of AI-enhanced social engineering by threat actors.






































