Sophisticated Attackers Hit the Heart of Wall Street
Hackers launched a coordinated wave of cyberattacks against major Wall Street money managers in recent days, targeting the information systems of Point72 Asset Management, Millennium Management, Citadel and Two Sigma Investments, according to people familiar with the matter, as reported by Bloomberg.
Point72 informed its investors on Wednesday that it had been attacked. The hedge fund's initial indications were that no client information was stolen, though the firm told investors it was still reviewing the incident, according to one person who asked not to be identified discussing non-public information. Spokespeople for Millennium, Point72 and Citadel declined to comment.
Two Sigma, which oversees $75 billion of assets, confirmed it repelled the attempt. 'Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,' a company spokesperson said. 'We continue to monitor the situation closely.'
The Weapon: AI-Cloned Voices
The attack featured voice phishing — known as vishing — in which cybercriminals use technology to mimic voices in phone calls or messages to trick employees into revealing sensitive information or granting system access, the people said.
Vinod Paul, president of Align Managed Services, a firm specializing in hedge fund cybersecurity, explained the scale shift AI has enabled. 'Before they could attack 50 entities in a targeted attack, now they can do 1,000,' Paul said. 'Hackers can also listen into a phone call and mimic the voice, tone and phrasings of the speakers to create fake calls.'
In June, a cybersecurity unit at Google published a blog post noting a wave of attacks this year against law firms and other professional services companies, also involving vishing techniques and, in some cases, individuals physically entering corporate offices posing as IT workers.
Will Wilson, chief executive of Antithesis — a firm backed by Jane Street that helps companies find and fix IT vulnerabilities — framed the structural threat plainly. 'The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale,' Wilson said. 'Everybody will have to seriously level up. Otherwise they are going to be in big trouble.'
Regulators Already Moving
The Financial Industry Regulatory Authority, which oversees broker-dealers and securities professionals, has been in contact with member firms about the recent attempted breaches, according to a separate person with knowledge of the matter. FINRA launched its Financial Intelligence Fusion Center in March — a secure portal for the regulator and its members to share intelligence about fraud threats and coordinate responses — specifically in response to increasingly sophisticated cyber and fraud threats directed at financial services firms.
The incidents also unfolded as U.S. authorities were racing to contain separate cyberattacks on water systems in several states that raised concerns about potential connections to Iran, though the two sets of attacks may be unrelated.
The Bottom Line
Capital rewards clear rules — and clear defenses. Wall Street firms handle trillions of dollars in daily transactions, and AI has now placed the tools for large-scale infiltration in the hands of rogue actors and potentially hostile states at a fraction of the former cost. The market will price this risk into compliance and technology budgets faster than any regulator can mandate it.
Free enterprise built these institutions; free enterprise will have to defend them. Firms that treat cybersecurity as overhead rather than infrastructure are writing blank checks to their adversaries.



