Major Hedge Funds Targeted in Coordinated Wave of Cyberattacks
Key Takeaways
- •A coordinated cyberattack campaign employing voice phishing techniques has targeted multiple major hedge funds and private equity firms, including Point72, Millennium Management, Two Sigma Investments, and Citadel.
- •Point72 Asset Management notified investors that its preliminary assessment found no client information was compromised, though the firm continues reviewing the incident.
- •Two Sigma, which manages approximately $75 billion in assets, confirmed it successfully blocked the attempted intrusion and found no impact to its data or systems.
- •FINRA has been in contact with member firms regarding the attempted breaches and launched a Financial Intelligence Fusion Center in March to help coordinate intelligence sharing about cyber and fraud threats.
- •Cybersecurity experts warn that artificial intelligence tools have significantly reduced the cost and increased the scale of attacks, forcing financial institutions to strengthen their defenses.

A sophisticated wave of cyberattacks has targeted major Wall Street firms in recent days, with hackers attempting to breach information systems at several prominent hedge funds and private equity firms, according to people familiar with the matter. Hedge funds are particularly attractive cyber targets because their systems house proprietary trading algorithms, real-time portfolio positions, and non-public market information — data that could be exploited for financial gain if exfiltrated.
Point72 Asset Management notified investors on Wednesday that it had been targeted in an attack. The hedge fund's preliminary assessment indicated that no client information had been compromised, though the firm said it was still reviewing the incident, according to a person briefed on the matter who asked not to be identified discussing non-public information.
The campaign also involved attempted intrusions at other major hedge funds, including Millennium Management, Two Sigma Investments, and Citadel, as well as several private equity firms, the sources said. The simultaneous targeting of multiple top-tier firms suggests a coordinated effort by a well-resourced actor, though the identity and motive remain unknown.
The attacks employed voice phishing, commonly known as "vishing" — a technique in which cybercriminals use technology to mimic voices in phone calls or messages to deceive employees into revealing sensitive information or granting system access.
Two Sigma, which manages approximately $75 billion in assets, confirmed that it successfully blocked the attempt to access sensitive data.
"Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems," a Two Sigma spokesperson said in a statement. "We continue to monitor the situation closely."
Spokespeople for Millennium, Point72, and Citadel declined to comment.
Cybersecurity incidents on Wall Street have escalated sharply over the past year, as artificial intelligence tools enable bad actors to conduct attacks more cheaply and at greater scale, according to Vinod Paul, president of Align Managed Services, a firm specializing in cybersecurity and IT services for hedge funds.
"Before they could attack 50 entities in a targeted attack, now they can do 1,000," Paul said. "Hackers can also listen into a phone call and mimic the voice, tone and phrasings of the speakers to create fake calls."
In June, a cybersecurity unit at Google published a blog post documenting a series of attacks this year against law firms and other professional services companies. Those incidents also involved vishing techniques and, in some cases, individuals physically entered corporate offices posing as IT workers, according to the post.
The Financial Industry Regulatory Authority (FINRA), which oversees broker-dealers and securities professionals, has been in contact with member firms regarding the recent attempted breaches, according to a separate person with knowledge of the matter.
FINRA launched the Financial Intelligence Fusion Center in March — a secure portal for FINRA and its member firms to share intelligence about fraud threats and coordinate responses. The initiative was created in response to increasingly sophisticated cyber and fraud threats being directed at financial services firms. A FINRA spokesperson declined to comment. The Securities and Exchange Commission has also been strengthening its cybersecurity oversight of the financial sector, having adopted rules in 2023 requiring registered investment advisers to maintain written cybersecurity policies and mandating that public companies disclose material cybersecurity incidents.
The incidents underscore the growing risk that scammers or hostile nation-states could leverage cutting-edge technologies to scale up attacks, in some cases demanding ransoms to unlock compromised data or systems. In the context of Wall Street, such breaches could affect firms and markets handling trillions of dollars in daily transactions.
Separately, though the events may be unrelated, US authorities have also been racing to contain cyberattacks on water systems in several states that have raised concerns about potential connections to Iran.
For decades, the financial industry operated with relatively lax software practices because the expertise required to execute sophisticated attacks was both specialized and uncommon, according to Will Wilson, CEO of Antithesis, a company that helps organizations identify and fix IT vulnerabilities and is backed by Jane Street.
"The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale," Wilson said. "Everybody will have to seriously level up. Otherwise they are going to be in big trouble."
This story was originally featured on Fortune.com.