Wall Street firms hit by vishing
- Hackers targeted major Wall Street firms and hedge funds in recent days, and Reuters reported on August 5 that the intrusions relied on phone-based deception. - Point72 confirmed an attack attempt and told investors no customer data or funds were affected, while sources said attackers sought employee-approved access. - Firms including Point72, Citadel and Two Sigma were identified in August 5 reporting, with reviews and investor notifications underway.
Hackers targeted major Wall Street financial firms and money managers in recent days by calling employees and trying to persuade them to grant access, according to Reuters and Bloomberg reports published on August 5. The campaign hit several hedge funds and private equity firms, the reports said, and did not center on a disclosed software flaw. Point72 Asset Management confirmed an attack attempt and told investors that no customer data or funds were affected. The incidents were described by people familiar with the matter as attempted intrusions into information systems rather than successful thefts of client assets. ### How were the attackers trying to get in? Phone calls were the reported entry point. Reuters said hackers used calls to trick employees into granting access, while Bloomberg described the activity as a wave of “vishing” attacks aimed at information systems at major money managers. In both accounts, the method relied on social engineering through staff interactions rather than exploitation of a named technical vulnerability. (msn.com) Yahoo Finance’s pickup of the Bloomberg report said the targets included Two Sigma Investments, Citadel and Point72 Asset Management, along with several private equity firms. InvestmentNews, citing the same episode, reported that attackers used AI-powered voice phishing in attempts to draw sensitive information from employees. Reuters did not independently attribute the campaign to a specific hacking group in the excerpts available through syndication. (msn.com) ### Which firms have been named publicly? Point72 is the clearest named firm to acknowledge an incident. Reuters, in a version republished by U.S. News and other outlets, said Point72 confirmed an attack attempt and said no customer data or funds were affected. Bloomberg-based reports also named Citadel, Millennium Management and Two Sigma as targets, though public comment from those firms was more limited in the syndicated coverage surfaced here. (finance.yahoo.com) Two Sigma said it was able to block the attackers and was reviewing the incident, according to secondary reports citing Bloomberg. Citadel and Point72 declined to comment in one summary of the Bloomberg reporting, while Reuters separately said Point72 had confirmed an attempted attack. Those differing public descriptions reflect the fact that several outlets were reporting from people familiar with confidential incidents unfolding over a period of days. (money.usnews.com) ### Why does this case stand out from a typical breach report? Reuters reported that the attackers sought to get employees to approve access, which points to internal identity and support processes as the pressure point in these attempts. Bloomberg’s description of AI-powered vishing suggests the callers were not relying on malware alone, but on convincing a person to take an action that would open a path into a system. (briefs.co) InvestmentNews said the campaign used AI-powered voice phishing, and Cybernews reported that AI-generated voices were used against employees at several firms. Those accounts indicate the operation was designed to sound credible enough to bypass normal skepticism during a service interaction, though the reports available here do not provide a full technical breakdown of the playbook. (msn.com) ### What has been the immediate impact so far? Point72 told investors that no customer data was accessed and no funds were affected, according to Reuters and follow-on reports. Reuters described the incidents as attempted cyberattacks, and the syndicated coverage available here does not say any of the named firms suffered a confirmed theft of client money. (investmentnews.com) Bloomberg’s report said the attacks were launched in recent days, and several firms were still assessing what had happened. That leaves the public picture focused on attempted access, named targets and internal reviews rather than a final accounting of damage. ### What happens next for the firms involved? August 5 reporting from Reuters and Bloomberg said firms were still reviewing the incidents and, in Point72’s case, communicating with investors about the attempted attack. (money.usnews.com) Any fuller public record is likely to come through additional company statements, regulatory disclosures or follow-up reporting naming the firms and the security steps they took after the calls. (msn.com) (bloomberg.com)