NewsMacroWall Street Firms Point72, Two Sigma, and Citadel Targeted in Social Engineering Phone Scams

Wall Street Firms Point72, Two Sigma, and Citadel Targeted in Social Engineering Phone Scams

Author: Hokanews·

Key Takeaways

  • Point72, Two Sigma, and Citadel were among the major Wall Street firms targeted by hackers using phone-based social engineering techniques, according to a Reuters report.
  • The attackers focused on manipulating employees through deception rather than exploiting software vulnerabilities, reflecting a broader shift toward human-focused attack methods.
  • Artificial intelligence tools have made voice phishing scams more personalized and harder to detect, increasing concerns among cybersecurity researchers and financial institutions.
  • U.S. regulators including the SEC and FINRA have tightened cybersecurity rules, with the SEC requiring public companies to report material cyber incidents within four business days.
  • Financial firms have responded by enhancing identity verification, employee training, and multi-channel confirmation procedures to reduce exposure to social engineering attacks.
Wall Street Firms Point72, Two Sigma, and Citadel Targeted in Social Engineering Phone Scams

Wall Street Firms Point72, Two Sigma, and Citadel Targeted in Social Engineering Phone Scams

Several major Wall Street investment firms have recently been targeted by hackers employing social engineering phone calls, according to a report from Reuters. The targeted institutions include Point72, Two Sigma, and Citadel, highlighting the escalating cybersecurity risks confronting some of the world's most influential financial organizations.

The attacks reportedly involved criminals attempting to manipulate employees through phone-based deception rather than exploiting traditional software vulnerabilities. This development has drawn significant attention from cybersecurity experts and financial industry observers, as it demonstrates how threat actors continue adapting their strategies to bypass increasingly sophisticated digital security systems.

The information was also highlighted by Cointelegraph through its official X account, drawing additional scrutiny from both the technology and financial communities.

Attackers Exploit Human Vulnerabilities

While financial institutions have significantly strengthened their cybersecurity defenses over the past decade — deploying advanced encryption, multi-factor authentication, AI-based monitoring systems, and sophisticated threat detection tools — attackers have increasingly redirected their efforts toward employees themselves.

Social engineering involves manipulating individuals into revealing confidential information, approving unauthorized requests, or granting access to protected systems. Rather than attempting to breach technical defenses directly, attackers impersonate legitimate representatives, colleagues, vendors, or trusted contacts to deceive their targets.

Phone-based social engineering, commonly referred to as voice phishing or "vishing," has emerged as one of the most prevalent methods employed by cybercriminals. In a typical attack, criminals contact employees while pretending to represent a legitimate organization, often impersonating IT staff, financial departments, business partners, or company executives. Attackers frequently create a sense of urgency, pressuring victims into immediate action — such as resetting passwords, verifying account information, approving transactions, or providing internal details.

Because the communication occurs through a familiar channel such as a phone call, victims may be more inclined to trust the interaction. Attackers commonly conduct reconnaissance before making contact, gathering information from public sources, professional networks, or previous data breaches to enhance the credibility of their schemes.

Why Financial Institutions Are Prime Targets

Financial institutions have long been attractive targets for cybercriminals due to the valuable assets, sensitive information, and high volumes of transactions they manage. Investment firms, hedge funds, and asset managers maintain access to proprietary research, trading strategies, client data, and confidential market information.

Firms such as Point72, Two Sigma, and Citadel operate within highly competitive financial environments where information security is paramount. A successful breach could potentially expose sensitive business intelligence or create opportunities for financial fraud. Beyond direct financial theft, attackers may also seek valuable information that could provide insight into investment decisions, trading activities, or corporate strategies.

AI Amplifies the Threat

Voice-based attacks have grown increasingly sophisticated as criminals combine traditional social engineering techniques with modern technology. Artificial intelligence tools have made it easier for attackers to create convincing messages, imitate communication patterns, and conduct more realistic interactions. Cybersecurity researchers have warned that AI could significantly increase the effectiveness of social engineering campaigns by making scams more personalized and harder to detect.

Financial institutions are particularly concerned because trust-based communication plays a central role in business operations. Executives, traders, analysts, and employees routinely communicate via phone calls, making it difficult to eliminate these risks entirely.

Industry Response and Regulatory Scrutiny

In response to the growing threat landscape, many financial companies have strengthened internal security procedures. Common measures include stricter identity verification requirements, enhanced employee training, improved monitoring systems, and stronger authentication processes. Some organizations have introduced additional confirmation steps before approving sensitive actions — for example, requiring employees to verify requests through separate communication channels rather than relying solely on phone conversations.

Financial regulators have increasingly focused on cybersecurity risks affecting banks, investment firms, and fintech companies. In the United States, the Securities and Exchange Commission adopted cybersecurity disclosure rules in 2023 requiring public companies to report material cybersecurity incidents within four business days, signaling that regulators now treat cyber resilience as a core operational and disclosure obligation. The Financial Industry Regulatory Authority (FINRA) has similarly issued repeated notices to member firms warning about social engineering schemes targeting broker-dealers and their clients. More broadly, social engineering has consistently ranked among the leading causes of confirmed data breaches across industries in major annual threat reports, underscoring why regulators view human-focused attack vectors as a systemic risk rather than an isolated operational concern.

Broader Implications for Global Markets

Cybersecurity incidents involving major financial institutions can have implications well beyond individual companies. Modern financial markets rely heavily on digital infrastructure, with trading systems, communication platforms, data networks, and investment operations all depending on secure technology environments. A significant cyber incident affecting a major financial firm could potentially disrupt operations, damage investor confidence, or trigger regulatory concerns.

Despite advances in cybersecurity technology, social engineering remains one of the most successful attack vectors. Security researchers often note that humans represent both the strongest and weakest elements of any cybersecurity system. Employees who recognize threats can prevent attacks before they cause harm, while those who unknowingly trust fraudulent communications may inadvertently provide attackers with pathways to bypass technical protections.

The reported attacks targeting Point72, Two Sigma, and Citadel underscore the evolving nature of cybersecurity threats facing the financial industry. As companies continue to strengthen their technical defenses, attackers are increasingly turning toward human-focused methods designed to exploit trust and communication — reinforcing the reality that effective cybersecurity requires not only advanced technology but also sustained investment in employee awareness, robust verification processes, and proactive risk management.

Source: Hokanews